An authentication method, chip, host and replaceable accessory
By setting access attributes for different storage areas within the chip to determine chip authentication, the problems of authentication data occupying storage space and being easily stolen are solved, achieving higher security and authentication accuracy.
Patent Information
- Application Number
- CN202210614460.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2022-03-11
- Filing Date
- 2022-05-26
- Publication Date
- 2026-03-03
- Estimated Expiration
- 2042-05-26
AI Technical Summary
In existing technologies, when chip authentication is performed using authentication data, the data occupies storage space and is easily stolen by third parties, leading to security risks.
The chip is certified by matching the data in the storage area with the access attributes of the storage area. The chip does not need to store certification data. The first storage area is set to be rewritable and the second storage area is set to be rewritable. The host determines whether the access attributes match.
This improves chip security, reduces the need to store authentication data, and enhances the chip's anti-theft capabilities.
Smart Images

Figure CN114968135B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of electronic technology, specifically to an authentication method, a chip, a host, and replaceable accessories. Background Technology
[0002] With the development of printing imaging technology, image forming devices such as printers, copiers, fax machines, and word processors have been widely used. These image forming devices all contain replaceable components, or imaging cartridges, that hold imaging materials (such as ink or toner), which are easily replaced by the user. These imaging cartridges typically contain an imaging cartridge chip.
[0003] The imaging process (e.g., printing process) of an image forming apparatus is mainly completed through the interaction between the imaging cartridge chip and the image forming apparatus. The image forming apparatus stores authentication information for the imaging cartridge chip, such as the model and color of the preset imaging cartridge. The imaging cartridge chip interacts with the image forming apparatus to verify the legitimacy of the imaging cartridge and provide imaging information during subsequent imaging processes.
[0004] In related technologies, the imaging cartridge chip records authentication information such as serial number, imaging cartridge model, color characteristics of the filling imaging material, and quality of the imaging material, as well as imaging information such as imaging date and image quality information obtained during subsequent imaging processes. The image quality information can be information on the amount of imaging material consumed or the amount of imaging material remaining in the imaging cartridge.
[0005] At the start of imaging, the image forming apparatus sends a detection signal to the imaging cartridge chip fixed on the imaging cartridge. Upon receiving the detection signal, the imaging cartridge chip generates a response based on its stored imaging information and sends it to the image forming apparatus. The image forming apparatus matches this response with the stored authentication information of the authenticated imaging cartridge chip. If a match is successful, it controls the application imaging cartridge to perform imaging. During the imaging process, both the image forming apparatus and the imaging cartridge chip record imaging information such as the printing date and the quality of the imaged object.
[0006] Common methods for authenticating image cartridge chips in image forming apparatuses involve reading authentication data from the chip. However, this authentication data consumes storage space on the image cartridge chip and is vulnerable to theft by third parties, posing a security risk. Summary of the Invention
[0007] In view of this, this application provides an authentication method, a chip, a host, and replaceable accessories to solve the problem in the prior art that chip authentication is performed using authentication data, which occupies the chip's storage space and is easily stolen by third parties, causing security risks.
[0008] In a first aspect, embodiments of this application provide an authentication method applied to a chip, the method comprising:
[0009] The receiver sends a first rewrite instruction, which is used to instruct the data in the first storage area to be rewritten;
[0010] Based on the access attributes of the first storage area, restrictions are placed on rewriting the data within the first storage area;
[0011] The system receives a second rewrite instruction sent by the host, the second rewrite instruction being used to instruct the data in the second storage area to be rewritten;
[0012] Based on the access attributes of the second storage area, the data in the second storage area is rewritten;
[0013] Receive a first read instruction sent by the host, the first read instruction being used to instruct the reading of data in the first storage area and the second storage area;
[0014] Send the data in the first storage area and the second storage area to the host.
[0015] In one possible implementation, restricting the rewriting of data in the first storage area based on the access attributes of the first storage area includes: prohibiting the rewriting of data in the first storage area based on the access attributes of the first storage area.
[0016] In one possible implementation, restricting the rewriting of data in the first storage area based on the access attributes of the first storage area includes: rewriting the data in the first storage area according to the restricted number of rewrites.
[0017] In one possible implementation, restricting the rewriting of data in the first storage area based on the access attributes of the first storage area includes: rewriting the data in the first storage area according to the direction of the restricted rewriting.
[0018] In one possible implementation, the method further includes:
[0019] The host receives a second read instruction sent by the host, the second read instruction being used to instruct the reading of lifespan reference information in the third storage area, and the host is used to determine whether the lifespan of the chip has been reached based on the lifespan reference information.
[0020] In one possible implementation, the method further includes:
[0021] The host receives a third read instruction sent by the host, the third read instruction being used to instruct the reading of authentication information in the fourth storage area, and the host is used to determine whether the chip has passed the preliminary authentication based on the authentication information.
[0022] In one possible implementation, the method further includes:
[0023] If the data in the second storage area is greater than or equal to a preset data threshold, then rewriting the data in the first storage area is permitted.
[0024] In one possible implementation, the addresses of the first storage area and the second storage area are not contiguous.
[0025] In one possible implementation, the chip further includes:
[0026] A first flag bit, which is used to indicate the access attributes of the first storage area;
[0027] The second flag bit is used to indicate the access attributes of the second storage area.
[0028] Secondly, embodiments of this application provide an authentication method applied to a host, the method comprising:
[0029] Send a first rewrite instruction to the chip, the first rewrite instruction being used to instruct the data in the first memory area to be rewritten;
[0030] Send a second rewrite instruction to the chip, the second rewrite instruction being used to instruct the data in the second memory area to be rewritten;
[0031] Send a first read instruction to the chip, the first read instruction being used to instruct the reading of data in the first storage area and the second storage area;
[0032] Receive data from the first and second storage areas sent by the chip;
[0033] Based on the data in the first and second storage areas, and the access attributes of the first and second storage areas, determine whether the chip has passed authentication;
[0034] If the data in the first storage area and the second storage area match the access attributes of the first storage area and the second storage area respectively, then the chip is determined to be certified.
[0035] If the data in the first storage area does not match the access attributes of the first storage area; or, if the data in the second storage area does not match the access attributes of the second storage area, then it is determined that the chip has failed authentication. Thirdly, embodiments of this application provide a chip, including:
[0036] The non-volatile memory includes a first storage area and a second storage area, wherein the access attribute of the first storage area is to restrict data rewriting, and the access attribute of the second storage area is to allow data rewriting;
[0037] The controller is configured to execute a portion of the methods in the first aspect.
[0038] In one possible implementation, the non-volatile memory further includes a third storage area for storing lifetime reference information;
[0039] The controller is also configured to execute a portion of the methods in the first aspect.
[0040] In one possible implementation, the non-volatile memory further includes a fourth storage area for storing authentication information;
[0041] The controller is also configured to execute a portion of the methods in the first aspect.
[0042] Fourthly, embodiments of this application provide a host, including:
[0043] processor;
[0044] Memory;
[0045] And one or more computer programs, wherein the one or more computer programs are stored in the memory, the one or more computer programs including instructions that, when executed by the host, cause the host to perform the method described in any one of the second parties.
[0046] Fifthly, embodiments of this application provide a replaceable accessory, including the chip described in any of the third aspects.
[0047] In this embodiment, the chip is certified by matching the access attributes of the pre-stored storage area with the access attributes of the detected storage area. The chip does not need to store certification data, which improves the chip's security. Attached Figure Description
[0048] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0049] Figure 1 This is a schematic diagram of an application scenario provided by an embodiment of this application;
[0050] Figure 2 This is a schematic diagram illustrating another application scenario provided by an embodiment of this application;
[0051] Figure 3 A schematic diagram of a storage partition provided in an embodiment of this application;
[0052] Figure 4 A flowchart illustrating an authentication method provided in an embodiment of this application;
[0053] Figure 5 This is another schematic diagram of a storage partition provided in an embodiment of this application;
[0054] Figure 6 A flowchart illustrating another authentication method provided in an embodiment of this application;
[0055] Figure 7 This is another schematic diagram of a storage partition provided in an embodiment of this application;
[0056] Figure 8 This is another schematic diagram of a storage partition provided in an embodiment of this application;
[0057] Figure 9 A structural block diagram of a chip is also provided for embodiments of this application;
[0058] Figure 10 This application also provides a structural block diagram of a chip. Detailed Implementation
[0059] To better understand the technical solution of this application, the embodiments of this application will be described in detail below with reference to the accompanying drawings.
[0060] It should be understood that the described embodiments are merely some, not all, of the embodiments in this application. All other embodiments obtained by those skilled in the art based on the embodiments in this application without inventive effort are within the scope of protection of this application.
[0061] The terminology used in the embodiments of this application is for the purpose of describing particular embodiments only and is not intended to be limiting of this application. The singular forms “a,” “the,” and “the” used in the embodiments of this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise.
[0062] It should be understood that the term "and / or" used in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this article generally indicates that the preceding and following related objects have an "or" relationship.
[0063] See Figure 1 This is a schematic diagram illustrating an application scenario provided by an embodiment of this application. For example... Figure 1 As shown, the electronic device includes a host and a chip, which can be a chip on a replaceable accessory used with the host. When the accessory is installed on the host, the host and the chip are communicatively connected. This communication connection can be via contacts, an antenna, or a coil. For example, the host can be a computer, mobile phone, tablet, image forming apparatus, etc., and the accessory can be a camera, USB memory, battery, data cable, charger, docking station, imaging box, etc.
[0064] For ease of understanding, the authentication scheme provided in this application is described in the following embodiments using an image forming apparatus and an imaging box as examples. However, this should not be construed as limiting the scope of protection of this application.
[0065] See Figure 2 This is a schematic diagram illustrating another application scenario provided by an embodiment of this application. For example... Figure 2 As shown, the imaging cartridge 2 includes an imaging cartridge chip 21, which has a volatile memory 211, a controller 212, and a non-volatile memory 213. The image forming apparatus 1 pre-stores access attributes of multiple storage areas in the non-volatile memory 213 of the imaging cartridge chip 21. The volatile memory 211 receives and stores commands sent by the image forming apparatus 1. The controller 212 executes the received commands sent by the image forming apparatus 1 according to the access attributes set in the imaging cartridge chip 21. The non-volatile memory 213 stores various data related to the imaging cartridge 2 or the image forming apparatus 1.
[0066] See Figure 3 This is a schematic diagram of a storage partition provided in an embodiment of this application. Figure 3The diagram illustrates a first storage area 213a and a second storage area 213b. The first storage area 213a is a rewrite-restricted area, while the second storage area 213b is a rewrite-allowed area. The two storage areas store different consumption data. Consumption data refers to the constantly changing parameter information recorded by the chip during use, which is crucial for the normal operation of the host. For example, the first consumption data stored in the first storage area 213a is data related to the imaging cartridge 2, and the second consumption data stored in the second storage area 213b is the number of printed pages. Additionally, a third storage area may be included, where the third consumption data indicates toner balance, etc. The specific meaning of the consumption data stored in different storage areas is different. In another possible implementation, the first consumption data indicates the percentage of toner consumed, and the second consumption data indicates the specific amount of toner consumed. In yet another possible implementation, the first storage area 213a and the second storage area 213b may also store the same consumption data. For example, both the first storage area 213a and the second storage area 213b store data related to the imaging box 2 or print page number data, etc., and this application embodiment does not impose specific limitations on this.
[0067] In existing technologies, chip authentication is performed using authentication data. However, this authentication data occupies the chip's storage space and is easily stolen by third parties, posing a security risk. This application provides an authentication scheme that determines whether a chip has passed authentication by matching the data in the storage area with the access attributes of the storage area. This eliminates the need to store authentication data within the chip and improves chip security.
[0068] See Figure 4 This is a flowchart illustrating an authentication method provided in an embodiment of this application. This method can be applied to... Figure 1 and Figure 2 The application scenarios shown are as follows: Figure 4 As shown, it mainly includes the following steps.
[0069] Step S401: The chip receives the first rewrite instruction sent by the host.
[0070] Specifically, the chip receives a write command sent by the host, which can point to the addresses of multiple memory areas in the chip's non-volatile memory 213. The content of the write command can be a subtraction command, such as subtracting 1 from the stored value from FF to FE. The data in the write command includes one or more of the following: imaging device ID, imaging cartridge installation date, customer data, toner consumption, and toner depletion flag. When the chip receives the write command from the host, it stores the write command in the volatile memory 211.
[0071] The chip's controller 212 determines the address pointed to by the write command stored in the volatile memory 211. When the write address points to the first memory area 213a, it determines that the write command is the first rewrite instruction.
[0072] Step S402: The chip restricts the rewriting of data in the first memory area based on the access attributes of the first memory area.
[0073] Specifically, if the aforementioned write command is a first rewrite instruction pointing to the first storage area 213a, then the controller 212 restricts the rewriting of the data in the first storage area 213a. The method of restricting the rewriting can be found in the description of the above embodiment, and will not be repeated here. In specific implementation, the data stored in the first storage area 213a may be data related to the imaging box 2, etc.
[0074] Step S403: The chip receives the second rewrite instruction sent by the host.
[0075] Specifically, the chip's controller 212 determines the address pointed to by the write command stored in the volatile memory 211. When the write address points to the second memory area 213b, it determines that the write command is a second rewrite instruction.
[0076] Step S404: The chip rewrites the data in the second memory area according to the access attributes of the second memory area.
[0077] Specifically, if the aforementioned write command is a second rewrite instruction pointing to the second storage area 213b, then the controller 212 performs normal rewrite of the data in the second storage area 213b. In specific implementation, the data stored in the second storage area 213b includes one or more of the following data: imaging device ID, imaging box installation date, customer data, toner remaining amount, toner consumption amount, and toner depletion indicator.
[0078] Step S405: The chip receives the first read command sent by the host.
[0079] Specifically, the first read instruction is used to instruct the reading of data from the first and second storage areas of the chip. The access attribute of the first storage area is restricted from data rewriting, while the access attribute of the second storage area is allowed to data rewriting. It is understood that after receiving the first and second rewrite instructions from the host, the data stored in the first and second storage areas has different characteristics. Based on these characteristics, the host can determine whether the chip is genuine, i.e., whether the chip has passed certification. Here, "genuine" refers to a product manufactured by a manufacturer or authorized by a manufacturer.
[0080] Step S406: The chip sends the data in the first storage area and the second storage area to the host.
[0081] Specifically, after receiving the first read instruction from the host, the chip returns the data in the first storage area and the second storage area to the host. For example, the first storage area is used to store first consumed data, and the second storage area is used to store second consumed data. After receiving the first read instruction from the host, the chip returns the first consumed data and the second consumed data to the host.
[0082] Step S407: The host determines whether the chip has passed authentication based on the data in the first storage area and the second storage area, as well as the access attributes of the first storage area and the second storage area.
[0083] Specifically, after the host sends a write command for a period of time, the host reads back the write status of multiple storage areas in the non-volatile memory 213. It identifies the access attributes of the data in each storage area based on whether the data was modified according to the write command, and determines whether the read access attributes of the multiple storage areas in the non-volatile memory 213 match the access attributes of multiple storage areas stored in the host. For example, the access attribute of the first storage area 213a is restricted from data modification, and the access attribute of the second storage area 213b is allowed to data modification. After reading the data stored in the first storage area 213a and the second storage area 213b, if the host identifies that the access attribute of the first storage area 213a is restricted from data modification, it considers that the access attribute of the first storage area 213a matches the access attribute of the first storage area 213a pre-stored in the host; if it identifies that the access attribute of the second storage area 213b is allowed to data modification, it considers that the access attribute of the second storage area 213b matches the access attribute of the second storage area 213b pre-stored in the host.
[0084] In practice, restrictions on data rewriting can include prohibiting data rewriting, limiting the number of rewrites, and restricting the direction of rewriting (allowing only data to increase or decrease), which will be explained below.
[0085] In one possible implementation, when "restricting data rewriting" means prohibiting data rewriting, if the host recognizes that the data in the first storage area 213a is the same as the data before receiving the rewrite command (for example, the data stored in the first storage area 213a before the rewrite is FF FF, and the data stored in the first data storage area 213a after the chip receives the rewrite command is still FF FF), and recognizes that the second storage area 213b has been correctly modified according to the rewrite command sent by the host, then the chip is considered to be genuine; otherwise, it is considered to be non-genuine.
[0086] In one possible implementation, when "restricting data rewriting" means restricting the number of rewrites, for example, allowing the host to rewrite once, the host sends multiple rewrite and read commands. If the host detects that the data in the first storage area 213a has only changed after receiving the first rewrite command and has not changed after receiving subsequent rewrite commands, and the host has correctly modified the first storage area 213a according to the rewrite commands sent by the host, then the chip is considered genuine; otherwise, it is considered non-genuine. Of course, those skilled in the art can set the restriction on the number of rewrites to 2, 3, or more times, etc., according to actual needs; this application embodiment does not impose specific limitations in this regard.
[0087] In one possible implementation, when "restricting data rewriting" restricts the direction of rewriting, the host sends a subtraction command or an addition command to the chip. For example, after receiving the rewrite command, the data in the first storage area 213a decreases unidirectionally (before rewriting, the data stored in the first storage area 213a was FF FF, and after the chip receives the rewrite command, the data stored in the first data storage area 213a is reduced to FF FE or smaller than before rewriting). If the second storage area 213b is found to have been correctly modified according to the rewrite command sent by the host, the chip is considered to be genuine; otherwise, it is considered to be non-genuine.
[0088] In one possible implementation, the host can pre-store access attributes for a first storage area and a second storage area. After the host obtains data from the first and second storage areas, it can directly determine whether the chip is genuine, i.e., whether the chip has passed authentication, based on the pre-stored access attributes. Specifically, after the host obtains data from the first and second storage areas, it can detect the access attributes of the first and second storage areas based on the data, and then determine whether the chip has passed authentication based on the matching of the detected access attributes with the pre-stored access attributes in the host. It can be understood that if the detected access attributes match the pre-stored access attributes, the chip is considered authenticated; if the detected access attributes do not match the pre-stored access attributes, the chip is considered unauthenticated.
[0089] In another possible implementation, the chip also stores a flag bit corresponding to the storage area. This flag bit is used to indicate the access attributes of the storage area, and the host can obtain the access attributes of the storage area by reading this flag bit. Step S403 specifically includes: reading the first flag bit in the chip to obtain the access attributes of the first storage area; reading the second flag bit in the chip to obtain the access attributes of the second storage area; and determining whether the chip has passed authentication based on the data in the first and second storage areas and the access attributes of the first and second storage areas. In a specific implementation, after the host obtains the data in the first and second storage areas, it can detect the access attributes of the first and second storage areas based on the data in the first and second storage areas, and then determine whether the chip has passed authentication based on the matching of the detected access attributes with the access attributes determined by the flag bit. It can be understood that if the detected access attributes match the pre-stored access attributes, the chip is determined to have passed authentication; if the detected access attributes do not match the pre-stored access attributes, the chip is determined to have failed authentication.
[0090] In one possible implementation, the host can pre-store reference data for the first and second storage areas. The host detects the access attributes of the first and second storage areas based on the data in the first and second storage areas. Specifically, after the host reads the data in the first and second storage areas, it compares the read data with the pre-stored reference data and determines the access attributes of the first and second storage areas based on the comparison result.
[0091] See Figure 5 This is a schematic diagram of another storage partition provided in an embodiment of this application. Figure 5 As shown, the non-volatile memory 213 has multiple storage areas and flag bits corresponding to each storage area. For example, the first flag bit 213c corresponds to the first storage area 213d, and the second flag bit 213e corresponds to the second storage area 213f. These flag bits indicate the access attributes of the corresponding storage areas. The first flag bit 213c indicates that the access attribute of the first storage area 213d is restricted from data reading and writing, while the second flag bit 213e indicates that the access attribute of the second storage area 213f is allowed to data reading and writing. In this way, without pre-storing the access attributes of the multiple storage areas in the host, the write status of the multiple storage areas can be read, and the access attributes of the multiple storage areas can be obtained. Then, based on the access attributes indicated by the flag bits, it can be determined whether the write status of the multiple storage areas matches the access attributes indicated by the corresponding flag bits.
[0092] Step S408: If the data in the first storage area and the second storage area match the access attributes of the first storage area and the second storage area respectively, then the chip is determined to have passed authentication; otherwise, the chip is determined to have failed authentication.
[0093] Specifically, if the host determines that the data in the first storage area and the second storage area match the access attributes of the first storage area and the second storage area respectively, then the chip is deemed to have passed authentication; if the host determines that the data in the first storage area does not match the access attributes of the first storage area, or the data in the second storage area does not match the access attributes of the second storage area, then the chip is deemed to have failed authentication.
[0094] In this embodiment, the chip is certified by matching the data in the storage area with the access attributes of the storage area. The chip does not need to store certification data, which improves the chip's security.
[0095] See Figure 6 This is a flowchart illustrating another authentication method provided in an embodiment of this application. This method is similar to... Figure 4 The difference in the illustrated embodiment is that, prior to step S401 described above, the following steps are also included.
[0096] Step S601: The chip receives the fourth read command sent by the host.
[0097] In this embodiment, before sending a rewrite instruction to the chip, the host first sends a read instruction to the chip to read the data in the first and second memory areas before rewriting. Specifically, the chip can receive a fourth read instruction from the host when it first establishes an electrical connection with the host.
[0098] Step S602: The chip sends the data in the first and second memory areas to the host.
[0099] After receiving the fourth read command from the host, the chip sends the data from the first and second memory areas to the host. It can be understood that the data in the first and second memory areas is the data from the first and second memory areas before the rewrite.
[0100] It is understood that in step S406, the data in the first and second storage areas sent by the chip to the host are the rewritten data in the first and second storage areas.
[0101] Furthermore, the host detects the access attributes of the first and second storage areas based on the data in the first and second storage areas. Specifically, this may include: the host comparing the data in the first and second storage areas before and after the rewrite with the data in the first and second storage areas after the rewrite, and determining the access attributes of the first and second storage areas based on the comparison results.
[0102] In other words, in this embodiment, before sending the first rewrite instruction and the second rewrite instruction to the chip, the host first sends a fourth read instruction to the chip to read the data in the first and second storage areas before rewriting; then, it sends the first rewrite instruction and the second rewrite instruction to the chip to rewrite the data in the first and second storage areas respectively; finally, it sends the first read instruction to the chip to read the data in the first and second storage areas after rewriting. The host compares the data in the first and second storage areas before rewriting with the data in the first and second storage areas after rewriting, and determines the access attributes of the first and second storage areas based on the comparison result.
[0103] Other contents of the embodiments of this application can be found in [reference]. Figure 4 The description of the embodiments shown is omitted here for the sake of brevity.
[0104] In this embodiment, since the access attributes of the first storage area 213a and the second storage area 213b are different, when the rewrite command for the first storage area 213a causes an address overflow, it may incorrectly rewrite the data in the second storage area 213b. Therefore, in a preferred implementation, the addresses of the first storage area 213a and the second storage area 213b can be set to be non-contiguous.
[0105] In one possible implementation, if the data in the second storage area is greater than or equal to a preset data threshold, then rewriting the data in the first storage area is permitted. For example, to protect the imaging device 1 from continuing to operate when the toner in the imaging cartridge 2 is depleted, and to ensure that the imaging device 1 correctly stops operating when the imaging cartridge 2 reaches the end of its lifespan, the second consumption data stored in the second storage area 213b is associated with the first consumption data stored in the first storage area 213a. If the second consumption data is the ink level data in the imaging cartridge 2, when the ink level data reaches a certain set value, rewriting the first consumption data in the first storage area 213a is permitted. When the imaging device 1 reads the imaging cartridge chip 21, it recognizes that the first consumption data has been changed, indicating that the access attributes of the first storage area 213a do not match the access attributes of the first storage area 213a pre-existing in the imaging device 1, and therefore, authentication of the imaging cartridge chip 21 fails.
[0106] See Figure 7 This is a schematic diagram of another storage partition provided in an embodiment of this application. Figure 7As shown in this embodiment, the non-volatile memory 213 further includes a third storage area 213g, which stores lifetime reference information. The access attribute of the third storage area 213g is read-only and cannot be rewritten. Based on the above embodiment, the method further includes: the host sending a second read instruction to the chip, which instructs the read of the lifetime reference information in the third storage area 213g. Further, the host can determine whether the chip's lifetime has been reached based on the lifetime reference information. For example, the lifetime reference information is capacity data, and consumption data is stored in the host. The host can compare the consumption data with the capacity data to determine whether the chip's lifetime has been reached.
[0107] In one possible implementation, to ensure the legitimacy of the host authentication chip is more reliable, an additional authentication procedure can be set up before performing the above authentication steps for preliminary authentication.
[0108] See Figure 8 This is a schematic diagram of another storage partition provided in an embodiment of this application. Figure 8 As shown in this embodiment, the non-volatile memory 213 further includes a fourth storage area 213h, which is used for authentication information. The access attribute of the fourth storage area 213h is read-only and cannot be rewritten. Based on the above embodiment, the method further includes: the host sending a third read instruction to the chip, which instructs the reading of the authentication information in the fourth storage area 213h. Further, the host can determine whether the chip has passed preliminary authentication based on the authentication information. If the chip has passed preliminary authentication, the authentication steps in the above method are executed; if the chip has failed preliminary authentication, the execution of the authentication steps in the above method is stopped. In specific implementation, the authentication information in the fourth storage area 213h can be authentication data such as digital signatures and authentication passwords; this embodiment does not impose specific limitations on this.
[0109] Corresponding to the above method embodiments, this application also provides a chip.
[0110] See Figure 9 This is a structural block diagram of a chip provided in an embodiment of this application. Figure 9 As shown, the chip 900 includes: a non-volatile memory 902, which includes a first storage area and a second storage area. The access attribute of the first storage area is to restrict data rewriting, and the access attribute of the second storage area is to allow data rewriting; and a controller 901, which is configured to execute some or all of the steps in the above method embodiments.
[0111] In one possible implementation, the non-volatile memory 902 further includes a third storage area for storing lifetime reference information;
[0112] In one possible implementation, the non-volatile memory 902 further includes a fourth memory area for storing authentication information.
[0113] Corresponding to the above method embodiments, this application also provides a host.
[0114] See Figure 10 This is a structural block diagram of a chip provided in an embodiment of this application. Figure 10 As shown, the host 1000 may include a processor 1001, a memory 1002, and a communication unit 1003. These components communicate via one or more buses. Those skilled in the art will understand that the server structure shown in the figure does not constitute a limitation on the embodiments of the present invention. It may be a bus topology or a star topology, and may include more or fewer components than shown, or combine certain components, or have different component arrangements.
[0115] The communication unit 1003 is used to establish a communication channel, thereby enabling the storage device to communicate with other devices.
[0116] The processor 1001 serves as the control center of the storage device, connecting various parts of the electronic device via various interfaces and lines. It executes software programs and / or modules stored in the memory 1002, and calls data stored in the memory to perform various functions of the electronic device and / or process data. The processor may be composed of integrated circuits (ICs), such as a single packaged IC or multiple packaged ICs with the same or different functions connected together. For example, the processor 1001 may consist only of a central processing unit (CPU). In this embodiment of the invention, the CPU may have a single processing core or include multiple processing cores.
[0117] The memory 1002 is used to store the execution instructions of the processor 1001. The memory 1002 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk or optical disk.
[0118] When the execution instructions in memory 1002 are executed by processor 1001, the host 1000 is able to perform some or all of the steps in the above method embodiments.
[0119] Corresponding to the above embodiments, this application also provides a replaceable accessory, which includes the chip described in the above embodiments. In practical applications, the replaceable accessory can be an imaging box, camera, USB memory, battery, data cable, charger, docking station, etc., and this application does not impose specific limitations on this.
[0120] In a specific implementation, this application also provides a computer storage medium, wherein the computer storage medium may store a program, and the program, when executed, may include some or all of the steps provided in the various embodiments of this application. The storage medium may be a magnetic disk, optical disk, read-only memory (ROM), or random access memory (RAM), etc.
[0121] In a specific implementation, this application also provides a computer program product, which includes executable instructions that, when executed on a computer, cause the computer to perform some or all of the steps in the above method embodiments.
[0122] In this application embodiment, "at least one" refers to one or more, and "more than one" refers to two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent the existence of A alone, the simultaneous existence of A and B, or the existence of B alone. A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one of the following" and similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, and c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple.
[0123] Those skilled in the art will recognize that the units and algorithm steps described in the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of electronic hardware and software. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.
[0124] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0125] In several embodiments provided by this invention, any function, if implemented as a software functional unit and sold or used as an independent product, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0126] The above description is merely a specific embodiment of the present invention. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this invention should be included within the protection scope of this invention. The protection scope of this invention should be determined by the scope of the claims.
Claims
1. An authentication method applied to a chip, the chip including a nonvolatile memory, the nonvolatile memory including a first storage area and a second storage area, characterized by, The method comprises: receiving a first rewrite instruction sent by a host, the first rewrite instruction being used to instruct rewriting data in a first storage area; rewriting data in the first storage area according to an access attribute of the first storage area; receiving a second rewrite instruction sent by the host, the second rewrite instruction being used to instruct rewriting data in a second storage area; rewriting data in the second storage area according to an access attribute of the second storage area; receiving a first read instruction sent by the host, the first read instruction being used to instruct reading data in the first storage area and the second storage area; sending data in the first storage area and the second storage area to the host, the host being used to judge whether the chip passes authentication according to the data in the first storage area and the second storage area and the access attribute of the first storage area and the second storage area, and judging that the chip passes authentication if the data in the first storage area and the second storage area respectively matches the access attribute of the first storage area and the second storage area, and judging that the chip does not pass authentication if the data in the first storage area does not match the access attribute of the first storage area or the data in the second storage area does not match the access attribute of the second storage area.
2. The method according to claim 1, wherein rewriting data in the first storage area according to the access attribute of the first storage area comprises prohibiting rewriting data in the first storage area according to the access attribute of the first storage area.
3. The method according to claim 1, wherein rewriting data in the first storage area according to the access attribute of the first storage area comprises rewriting data in the first storage area according to a limited number of times of rewriting.
4. The method according to claim 1, wherein rewriting data in the first storage area according to the access attribute of the first storage area comprises rewriting data in the first storage area according to a limited direction of rewriting.
5. The method of claim 1, wherein, The method further comprises: receiving a second read instruction sent by the host, the second read instruction being used to instruct reading service life reference information in a third storage area, the host being used to judge whether the service life of the chip is reached according to the service life reference information.
6. The method of claim 1, wherein, The method further comprises: receiving a third read instruction sent by the host, the third read instruction being used to instruct reading authentication information in a fourth storage area, the host being used to judge whether the chip passes preliminary authentication according to the authentication information.
7. The method of claim 1, wherein, The method further comprises: if the data in the second storage area is greater than or equal to a preset data threshold, rewriting data in the first storage area is allowed.
8. The method of claim 1, wherein, The addresses of the first storage area and the second storage area are discontinuous.
9. The method of claim 1, wherein, The chip further comprises: a first flag, the first flag being used to indicate the access attribute of the first storage area. A second flag is used to indicate an access attribute of the second storage area.
10. An authentication method characterized by, The method is applied to a host, the host is in communication connection with a chip, the chip comprises a non-volatile memory, the non-volatile memory comprises a first storage area and a second storage area, and the method comprises: sending a first rewrite instruction to the chip, the first rewrite instruction being used to instruct rewriting data in the first storage area; sending a second rewrite instruction to the chip, the second rewrite instruction being used to instruct rewriting data in the second storage area; sending a first read instruction to the chip, the first read instruction being used to instruct reading data in the first storage area and the second storage area; receiving data in the first storage area and the second storage area sent by the chip; judging whether the chip passes authentication according to the data in the first storage area and the second storage area and access attributes of the first storage area and the second storage area; if the data in the first storage area and the second storage area respectively matches the access attributes of the first storage area and the second storage area, judging that the chip passes authentication; if the data in the first storage area does not match the access attribute of the first storage area, or the data in the second storage area does not match the access attribute of the second storage area, judging that the chip does not pass authentication.
11. A chip, characterized by comprise: a non-volatile memory comprising a first storage area and a second storage area, an access attribute of the first storage area being to restrict data rewriting, and an access attribute of the second storage area being to allow data rewriting; a controller configured to: receive a first rewrite instruction sent by a host, the first rewrite instruction being used to instruct rewriting data in the first storage area; restrict rewriting data in the first storage area according to the access attribute of the first storage area; receive a second rewrite instruction sent by the host, the second rewrite instruction being used to instruct rewriting data in the second storage area; rewrite data in the second storage area according to the access attribute of the second storage area; receive a first read instruction sent by the host, the first read instruction being used to instruct reading data in the first storage area and the second storage area; send data in the first storage area and the second storage area to the host, the host being used to judge whether the chip passes authentication according to the data in the first storage area and the second storage area and the access attributes of the first storage area and the second storage area; if the data in the first storage area and the second storage area respectively matches the access attributes of the first storage area and the second storage area, judging that the chip passes authentication; if the data in the first storage area does not match the access attribute of the first storage area, or the data in the second storage area does not match the access attribute of the second storage area, judging that the chip does not pass authentication; if data in the second storage area is greater than or equal to a preset data threshold, allowing rewriting data in the first storage area.
12. The chip of claim 11, wherein, The limiting of the rewriting of the data in the first storage area according to the access attribute of the first storage area comprises: The rewriting of the data in the first storage area is prohibited according to the access attribute of the first storage area.
13. The chip of claim 11, wherein, The limiting of the rewriting of the data in the first storage area according to the access attribute of the first storage area comprises: The rewriting of the data in the first storage area is limited according to the number of times of rewriting.
14. The chip of claim 11, wherein, The limiting of the rewriting of the data in the first storage area according to the access attribute of the first storage area comprises: The rewriting of the data in the first storage area is limited according to the direction of rewriting.
15. The chip of claim 11, wherein The non-volatile memory further comprises a third storage area, and the third storage area is configured to store service life reference information. The controller is further configured to receive a second read instruction sent by the host, and the second read instruction is configured to instruct to read the service life reference information in the third storage area, and the host is configured to determine whether the service life of the chip is reached according to the service life reference information.
16. The chip of claim 11, wherein The non-volatile memory further comprises a fourth storage area, and the fourth storage area is configured to store authentication information. The controller is further configured to receive a third read instruction sent by the host, and the third read instruction is configured to instruct to read the authentication information in the fourth storage area, and the host is configured to determine whether the chip passes the preliminary authentication according to the authentication information.
17. The chip of claim 11, wherein, The addresses of the first storage area and the second storage area are discontinuous.
18. The chip of claim 11, wherein, The chip further comprises: A first flag, and the first flag is configured to indicate the access attribute of the first storage area; A second flag, and the second flag is configured to indicate the access attribute of the second storage area.
19. A host, characterized by Comprise: A processor; A memory; And one or more computer programs, wherein the one or more computer programs are stored in the memory, and the one or more computer programs comprise instructions, and when the instructions are executed by the host, the host is caused to execute the method of claim 10.
20. A replaceable accessory characterized by, Comprise the chip of any one of claims 11-18.
Citation Information
Patent Citations
Data storage method of consumable chip, consumable chip and consumable
CN109532236A
Access control method, device and apparatus and storage medium
CN110414268A
Consumable chip for consumable box and data processing method thereof
CN113064754A