A two-way authentication method between mouse and PC

By adopting two-way authentication methods and encryption technology in intelligent voice mice, the problem of insufficient identity authentication security in the existing technology is solved, and higher data transmission security and communication uniqueness are achieved.

CN115134151BActive Publication Date: 2025-05-16HEFEI MADAO INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210753325.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-29
Publication Date
2025-05-16
Estimated Expiration
2042-06-29

AI Technical Summary

Technical Problem

The identity authentication mechanism of existing smart voice mice is poorly secure and is easily cracked, resulting in the risk of data leakage.

Method used

The two-way authentication method between the mouse and the PC terminal is adopted, through handshake instructions and two-way authentication interaction, the Session_key key encryption and random numbers are used to prevent playback, increasing the cost of reverse analysis.

Benefits of technology

Effectively prevent Session_key key leakage, prevent replay attacks, increase reverse analysis costs, and improve data transmission security and communication uniqueness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115134151B_ABST
    Figure CN115134151B_ABST
Patent Text Reader

Abstract

The invention relates to interactive authentication, and in particular to a two-way authentication method between a mouse and a PC end. The PC end obtains mouse device information necessary for authentication, and sends the PC end device information necessary for authentication to the mouse; the PC end sends a handshake instruction to the mouse; the mouse initiates a two-way authentication request after receiving the handshake instruction, and the mouse and the PC end perform two-way authentication interaction; the two-way authentication is completed between the mouse and the PC end. The technical solution provided by the invention can effectively overcome the defects of the prior art that the identity authentication mechanism between the mouse and the PC end has poor security and is easy to be cracked.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to interactive authentication, and in particular to a two-way authentication method between a mouse and a PC. Background Art

[0002] With the development of technology, the functions of traditional mice can no longer meet the daily needs of users. In recent years, as intelligent voice technology has been gradually applied to keyboard and mouse products, the mouse has been transformed from a traditional attribute to an intelligent voice mouse with AI attributes, and many voice keyboard and mouse products have appeared on the market. However, these intelligent keyboards and mice only use simple mouse identification code recognition to achieve identity authentication between the client and the hardware. After passing the identity authentication, they can obtain communication permissions, which has a low security factor and is easy to be cracked.

[0003] At present, because the intelligent voice keyboard and mouse support voice interaction, there are mechanisms such as communication between the PC and the mouse, and data stream transmission between the PC and the engine, and these mechanisms all rely on the client software to implement. In order to prevent the software from being downloaded by other users and paired with other hardware products to cause data leakage, it is necessary to develop a two-way authentication mechanism between the mouse and the PC to ensure the uniqueness of the communication between the mouse and the PC and the security of data transmission. Summary of the invention

[0004] 1. Technical issues to be resolved

[0005] In view of the above-mentioned shortcomings of the prior art, the present invention provides a two-way authentication method between a mouse and a PC, which can effectively overcome the defects of the prior art that the identity authentication mechanism between the mouse and the PC is poor in security and easy to be cracked.

[0006] (II) Technical solution

[0007] To achieve the above objectives, the present invention is implemented through the following technical solutions:

[0008] A two-way authentication method between a mouse and a PC includes the following steps:

[0009] S1. The PC obtains the mouse device information required for authentication, and sends the PC device information required for authentication to the mouse;

[0010] S2, PC sends handshake command to mouse;

[0011] S3, after receiving the handshake command, the mouse initiates a two-way authentication request, and the mouse and the PC perform two-way authentication interaction;

[0012] S4. Complete two-way authentication between the mouse and the PC.

[0013] Preferably, in S3, two-way authentication interaction is performed between the mouse and the PC, including:

[0014] S31, the mouse sends slave verification information to the PC;

[0015] S32, the PC verifies the slave verification information, and sends the obtained slave information verification result and the host verification information to the mouse;

[0016] S33, the mouse verifies the slave information verification result and the host verification information sent by the PC, and sends the host information verification result to the PC;

[0017] S34. The PC compares the encrypted data of the local information with the host information verification result, and sends the authentication result to the mouse according to the comparison result.

[0018] Preferably, in S31, the mouse sends slave verification information to the PC, including:

[0019] Use Session_key to encrypt the XOR result of Mouse_Finger and Rondom1 with AES, and send the encrypted result to the PC.

[0020] Among them, Session_key is the AES key, which is obtained by encrypting Version and MAC; Rondom1 is a 16-byte random number generated by the mouse.

[0021] Preferably, in S32, the PC verifies the slave verification information, and sends the obtained slave information verification result and the host verification information to the mouse, including:

[0022] Use the Session_key key to parse the XOR result of Mouse_Finger and Rondom1;

[0023] XOR the XOR result of Mouse_Finger and Rondom1 with Mouse_Finger to get Rondom1;

[0024] Use Session_key to perform AES encryption on the XOR result of PC_Finger, Rondom2, and Rondom1, and send the encrypted result to the mouse;

[0025] Among them, Rondom2 is a 16-byte random number generated by the PC.

[0026] Preferably, in S33, the mouse verifies the slave information verification result and the host verification information sent by the PC, and sends the host information verification result to the PC, including:

[0027] Use the Session_key key to parse the XOR result of PC_Finger, Rondom2, and Rondom1;

[0028] XOR the XOR result of PC_Finger, Rondom2, and Rondom1 with Rondom1 to obtain the XOR result of PC_Finger and Rondom2;

[0029] XOR the XOR result of PC_Finger and Rondom2 with PC_Finger to obtain Rondom2;

[0030] The SDBM algorithm is used to calculate the Hash value of PC_Finger, and the Hash value of PC_Finger and Rondom2 are encrypted with MD5, and the encrypted result is sent to the PC.

[0031] Preferably, in S34, the PC compares the data obtained by encrypting the local information with the host information verification result, and sends the authentication result to the mouse according to the comparison result, including:

[0032] The SDBM algorithm is used to calculate the hash value of the local PC_Finger, and the hash value of the local PC_Finger and the local Rondom2 are encrypted with MD5, and the encryption result is compared with the host information verification result sent by the mouse;

[0033] If the comparison results are consistent, an authentication success result is sent to the mouse, otherwise an authentication failure result is sent to the mouse.

[0034] Preferably, the two-way authentication interaction between the mouse and the PC should complete all authentication work within 30 seconds from the start of the handshake. If the two-way authentication interaction between the mouse and the PC exceeds 30 seconds from the start of the handshake, the PC sends an authentication failure result to the mouse.

[0035] Preferably, in S1, the PC obtains the mouse device information necessary for authentication, and sends the PC device information necessary for authentication to the mouse, including:

[0036] The PC sends instructions to obtain mouse device information to the mouse one by one. The mouse feeds back the mouse device information including Mouse_Finger, Version, and MAC to the PC in sequence. At the same time, the PC actively sends the PC device information including PC_Finger to the mouse.

[0037] Preferably, the Mouse_Finger is the unique identification code of the mouse, with a total length of 16 bytes; the PC_Finger is the host version number of the PC, with a total length of 16 bytes; the Version is the firmware version number of the mouse, with a total length of 4 bytes; and the MAC is the MAC address of the mouse, with a total length of 6 bytes.

[0038] (III) Beneficial effects

[0039] Compared with the prior art, the two-way authentication method between a mouse and a PC provided by the present invention has the following beneficial effects:

[0040] 1) The mouse's Session_key is encrypted and stored internally, so hackers cannot read it directly from the Flash. The PC's Session_key information is scattered in multiple places. For example, a part of the code is extracted as the Session_key to generate a sea of ​​key garbage. Image steganography and other methods are used to effectively prevent the Session_key from being leaked.

[0041] 2) Hackers monitor USB or Bluetooth communications and replay requests. The slave authentication information and host authentication information in the two-way authentication mechanism both contain random numbers, which can effectively prevent replay;

[0042] 3) When hackers use decompilation, online debugging tools or similar hook tools to reverse analyze the program flow on the PC side and perform binary or virtual machine level byte patch, on the one hand, the reverse cost is increased by adding caller signature checks, code obfuscation, and exe packing. On the other hand, each time the PC is started and attempts to connect to the Internet, the MD5 of important components is recalculated and uploaded to the server for verification, which can effectively prevent reverse analysis. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the prior art descriptions are briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention, and for ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0044] Figure 1 It is a schematic diagram of the process of the present invention;

[0045] Figure 2 It is a schematic diagram of the process of device information interaction between the PC and the mouse in the present invention;

[0046] Figure 3The figure is a flow chart of the two-way authentication interaction between the mouse and the PC in the present invention. DETAILED DESCRIPTION

[0047] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0048] A two-way authentication method between a mouse and a PC, such as Figure 1 As shown, S1, the PC obtains the mouse device information required for authentication, and sends the PC device information required for authentication to the mouse;

[0049] S2, PC sends handshake command to mouse;

[0050] S3, after receiving the handshake command, the mouse initiates a two-way authentication request, and the mouse and the PC perform two-way authentication interaction;

[0051] S4. Complete two-way authentication between the mouse and the PC.

[0052] like Figure 2 As shown, in S1, the PC obtains the mouse device information required for authentication, and sends the PC device information required for authentication to the mouse, including:

[0053] The PC sends instructions to obtain mouse device information to the mouse one by one. The mouse feeds back the mouse device information including Mouse_Finger, Version, and MAC to the PC in sequence. At the same time, the PC actively sends the PC device information including PC_Finger to the mouse.

[0054] In the technical solution of the present application, Mouse_Finger is the unique identification code of the mouse, with a total length of 16 bytes; PC_Finger is the host version number of the PC, with a total length of 16 bytes; Version is the firmware version number of the mouse, with a total length of 4 bytes; MAC is the MAC address of the mouse, with a total length of 6 bytes.

[0055] like Figure 3 As shown, in S3, two-way authentication interaction is performed between the mouse and the PC, including:

[0056] S31, the mouse sends slave verification information to the PC;

[0057] S32, the PC verifies the slave verification information, and sends the obtained slave information verification result and the host verification information to the mouse;

[0058] S33, the mouse verifies the slave information verification result and the host verification information sent by the PC, and sends the host information verification result to the PC;

[0059] S34. The PC compares the encrypted data of the local information with the host information verification result, and sends the authentication result to the mouse according to the comparison result.

[0060] ① The mouse sends slave verification information to the PC, including:

[0061] Use Session_key to encrypt the XOR result of Mouse_Finger and Rondom1 with AES, and send the encrypted result to the PC.

[0062] Among them, Session_key is the AES key, which is obtained by encrypting Version and MAC; Rondom1 is a 16-byte random number generated by the mouse.

[0063] The information of slave verification information Challenge1 is shown in the following table:

[0064]

[0065] ②The PC verifies the slave verification information and sends the slave information verification result and the host verification information to the mouse, including:

[0066] Use the Session_key key to parse the XOR result of Mouse_Finger and Rondom1;

[0067] XOR the XOR result of Mouse_Finger and Rondom1 with Mouse_Finger to get Rondom1;

[0068] Use Session_key to perform AES encryption on the XOR result of PC_Finger, Rondom2, and Rondom1, and send the encrypted result to the mouse;

[0069] Among them, Rondom2 is a 16-byte random number generated by the PC.

[0070] The slave information verification result and the master verification information Response1+Challenge2 are shown in the following table:

[0071]

[0072] ③ The mouse verifies the slave information verification result and the host verification information sent by the PC, and sends the host information verification result to the PC, including:

[0073] Use the Session_key key to parse the XOR result of PC_Finger, Rondom2, and Rondom1;

[0074] XOR the XOR result of PC_Finger, Rondom2, and Rondom1 with Rondom1 to obtain the XOR result of PC_Finger and Rondom2;

[0075] XOR the XOR result of PC_Finger and Rondom2 with PC_Finger to obtain Rondom2;

[0076] The SDBM algorithm is used to calculate the Hash value of PC_Finger, and the Hash value of PC_Finger and Rondom2 are encrypted with MD5, and the encrypted result is sent to the PC.

[0077] The information of host information verification result Response2 is shown in the following table:

[0078] 16 bytes (char) MD5(H(PC_Finger), Rondom2)

[0079] ④The PC compares the encrypted data of the local information with the host information verification result, and sends the authentication result to the mouse according to the comparison result, including:

[0080] The SDBM algorithm is used to calculate the hash value of the local PC_Finger, and the hash value of the local PC_Finger and the local Rondom2 are encrypted with MD5, and the encryption result is compared with the host information verification result sent by the mouse;

[0081] If the comparison results are consistent, an authentication success result is sent to the mouse, otherwise an authentication failure result is sent to the mouse.

[0082] The authentication result information is shown in the following table:

[0083] 4 bytes (int) Result

[0084] AES: AES128 ECB mode

[0085] MD5: MD5 128 bits

[0086] H:SDBM Hash

[0087] In the above technical solution, the two-way authentication interaction between the mouse and the PC should complete all authentication work within 30 seconds from the start of the handshake. If the two-way authentication interaction between the mouse and the PC exceeds 30 seconds from the start of the handshake, the PC sends an authentication failure result to the mouse.

[0088] In the technical solution of this application, there are two communication methods between the mouse and the PC: BLE and USB. BLE communication has the risk of packet interception or data tampering. In order to solve this problem, the format of the data packet is fixed and verification information is added to the data packet to ensure the integrity and accuracy of the data packet. The data format of the data packet is shown in the following table:

[0089] Start Sequence Datalength Data CRC(Data) 1 Byte 1 Byte 4Byte NByte 4Byte

[0090] Start: As the starting data of each group of data, it has a fixed value of 0XFE;

[0091] Sequence: Serial number. The serial number increases in sequence. The PC output data and the mouse output data share the same serial number. If the serial numbers of two consecutive groups of data packets are not consecutive, it can be determined that there are lost data packets.

[0092] Data length: indicates the length of the data, not the total packet length. The total packet length is Data length + 10.

[0093] Data: valid data payload;

[0094] CRC(Data): Cyclic redundancy check data of Data, with a fixed length of four bytes, used to detect or verify the integrity of a single data packet, effectively preventing the data packet from being tampered with and causing abnormal authentication results.

[0095] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements will not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A two-way authentication method between a mouse and a PC, characterized in that: The following steps are involved: S1. The PC obtains the mouse device information required for authentication, and sends the PC device information required for authentication to the mouse; S2, PC sends handshake command to mouse; S3, after receiving the handshake command, the mouse initiates a two-way authentication request, and the mouse and the PC perform two-way authentication interaction; S4. Complete two-way authentication between the mouse and the PC. In S3, two-way authentication interaction is performed between the mouse and the PC, including: S31, the mouse sends slave verification information to the PC; S32, the PC verifies the slave verification information, and sends the obtained slave information verification result and the host verification information to the mouse; S33, the mouse verifies the slave information verification result and the host verification information sent by the PC, and sends the host information verification result to the PC; S34, the PC compares the encrypted data of the local information with the host information verification result, and sends the authentication result to the mouse according to the comparison result; In S31, the mouse sends slave verification information to the PC, including: Use Session_key to encrypt the XOR result of Mouse_Finger and Rondom1 with AES, and send the encrypted result to the PC. Among them, Session_key is the AES key, which is obtained by encrypting Version and MAC; Rondom1 is a 16-byte random number generated by the mouse; In S32, the PC verifies the slave verification information and sends the obtained slave information verification result and the host verification information to the mouse, including: Use the Session_key key to parse the XOR result of Mouse_Finger and Rondom1; XOR the XOR result of Mouse_Finger and Rondom1 with Mouse_Finger to get Rondom1; Use Session_key to perform AES encryption on the XOR result of PC_Finger, Rondom2, and Rondom1, and send the encrypted result to the mouse; Among them, Rondom2 is a 16-byte random number generated by the PC; In S33, the mouse verifies the slave information verification result and the host verification information sent by the PC, and sends the host information verification result to the PC, including: Use the Session_key key to parse the XOR result of PC_Finger, Rondom2, and Rondom1; XOR the XOR result of PC_Finger, Rondom2, and Rondom1 with Rondom1 to obtain the XOR result of PC_Finger and Rondom2; XOR the XOR result of PC_Finger and Rondom2 with PC_Finger to obtain Rondom2; The SDBM algorithm is used to calculate the Hash value of PC_Finger, and the Hash value of PC_Finger and Rondom2 are encrypted with MD5, and the encrypted result is sent to the PC. In S34, the PC side compares the encrypted data of the local information with the host information verification result, and sends the authentication result to the mouse according to the comparison result, including: The SDBM algorithm is used to calculate the hash value of the local PC_Finger, and the hash value of the local PC_Finger and the local Rondom2 are encrypted with MD5, and the encryption result is compared with the host information verification result sent by the mouse; If the comparison results are consistent, the authentication success result is sent to the mouse, otherwise the authentication failure result is sent to the mouse; The Mouse_Finger is the unique identification code of the mouse, with a total length of 16 bytes; the PC_Finger is the host version number of the PC, with a total length of 16 bytes; the Version is the firmware version number of the mouse, with a total length of 4 bytes; and the MAC is the MAC address of the mouse, with a total length of 6 bytes.

2. The two-way authentication method between the mouse and the PC according to claim 1, characterized in that: The two-way authentication interaction between the mouse and the PC should complete all authentication work within 30 seconds from the start of the handshake. If the two-way authentication interaction between the mouse and the PC exceeds 30 seconds from the start of the handshake, the PC sends an authentication failure result to the mouse.

3. The two-way authentication method between a mouse and a PC according to claim 1 or 2, characterized in that: In S1, the PC obtains the mouse device information required for authentication, and sends the PC device information required for authentication to the mouse, including: The PC sends instructions to obtain mouse device information to the mouse one by one. The mouse feeds back the mouse device information including Mouse_Finger, Version, and MAC to the PC in sequence. At the same time, the PC actively sends the PC device information including PC_Finger to the mouse.

Citation Information

Patent Citations

  • Mouse device with digital certificate function

    CN103116413A

  • Identity authentication method and system

    CN104579694A