A Bidirectional Network Access Authentication Method, Device and Board Card

Through the two-way network access authentication method of board and card, the problem of system functions being unavailable due to functional board failure is solved, and environmental adaptability, computing capability and reliability are improved in the information processing system.

CN115603940BActive Publication Date: 2025-06-10位银星
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211042464.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-29
Publication Date
2025-06-10
Estimated Expiration
2042-08-29

AI Technical Summary

Technical Problem

In existing information processing systems, functional boards can only complete a single function. When a certain functional board fails, this function in the entire system is unavailable.

Method used

The board-card two-way network access authentication method is adopted. The first information including numbering information, hardware driver and service function information is extracted in nonvolatile memory, and the second information is sent for triggering the bidirectional time verification of the control unit. If the verification is successful, the service loading frame will be sent to obtain and verify the correctness of the service loading frame. If it is correct, the function code will be obtained and stored in dynamic random access memory, and the service calculation will be performed according to the function code.

Benefits of technology

By standardizing the board design, different functions can be realized on limited hardware, the system's environmental adaptability and computing capabilities can be improved, and software code switching will be improved when the board fails, improving the system's reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115603940B_ABST
    Figure CN115603940B_ABST
Patent Text Reader

Abstract

The present invention provides a method, device and board card for two-way network access authentication, which relates to the technical field of missile-borne information processing. It includes extracting first information from a non-volatile memory, where the first information includes serial number information, hardware drivers and service function information; sending second information, which includes serial number information, service function information and version information in the hardware drivers. The second information is used to trigger the control unit to perform two-way time verification on the network access legality of the board card end. If the verification is successful, a service loading frame is sent; obtaining and verifying whether the service loading frame is correct. If the service loading frame is correct, the function code is obtained and stored in the dynamic random access memory. In the present invention, the board card starts the hardware driver and service loading function from the non-volatile memory, while the control unit conducts network communication and service loading with the board card and issues the selected function code to the specified board card, so that there is no information leakage before the board card is transported and used.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information processing, and in particular, to a method and apparatus for bidirectional network access authentication of a board card and a board card. Background Art

[0002] In the current field of missile-borne information processing, a method of building an information processing subsystem with multiple functional board cards is mostly used to complete the processing of link data. Functional board card 1 to functional board card N are dedicated board cards that complete a single item-by-item function. The calculation and control unit parses the link data and calls the corresponding functional board card according to the corresponding type identifier in the message to complete information processing. After the information processing is completed, the result is output. However, the functional board card can only complete one specific function. When a certain functional board card fails, this function in the entire system becomes unavailable. Summary of the Invention

[0003] The purpose of the present invention is to provide a method and apparatus for bidirectional network access authentication of a board card and a board card to improve the above problems. To achieve the above purpose, the technical solutions adopted by the present invention are as follows:

[0004] In a first aspect, the present application provides a method for bidirectional network access authentication of a board card for the board card side, including: extracting first information in a non-volatile memory, where the first information includes number information, a hardware driver, and service function information, the service function information includes an executable function code of the board card, and the number information includes a unique number corresponding to the board card; sending second information, where the second information includes the version information of the number information, the service function information, and the hardware driver, and the second information is used to trigger the control unit to perform bidirectional time verification on the network access legality of the board card side. If the verification is successful, a service loading frame is sent; obtaining and verifying whether the service loading frame is correct. If the service loading frame is correct, a function code is obtained and stored in a dynamic random access memory, and service calculation is performed according to the function code in the dynamic random access memory.

[0005] In a second aspect, the present application further provides a bidirectional network access authentication device for a board card, including: a first extraction unit, configured to extract first information from a non-volatile memory, where the first information includes number information, a hardware driver, and service function information, the service function information includes executable function codes of the board card, and the number information includes a unique number corresponding to the board card; a first sending unit, configured to send second information, where the second information includes the number information, the version information in the service function information and the hardware driver, and the second information is used to trigger the control unit to perform bidirectional time verification on the network access legality of the board card side. If the verification is successful, a service loading frame is sent; a first verification unit, configured to obtain and verify whether the service loading frame is correct. If the service loading frame is correct, a function code is obtained and stored in a dynamic random access memory, and service calculation is performed according to the function code in the dynamic random access memory.

[0006] In a third aspect, the present application further provides a board card, including:

[0007] a memory, configured to store a computer program;

[0008] a processor, configured to implement the steps of the bidirectional network access authentication method for the board card when executing the computer program.

[0009] The beneficial effects of the present invention are as follows:

[0010] The present invention standardizes the design of the board card, that is, this method is used for standardizing the design of the board card. The so-called standardization design mentioned herein refers to a board card with a unified board card hardware architecture. Through the above design, when the entire system requires corresponding functions, different functions can be implemented on limited hardware according to different usage scenarios, improving the environmental adaptability of the system; software codes for implementing the same function can also be loaded on multiple board card hardwares at the same time, and multiple board cards work simultaneously to improve the computing power of the system; in addition, when a certain board card fails, the function can be implemented on another board card by loading software codes, improving the reliability of the system.

[0011] Other features and advantages of the present invention will be described in the subsequent description, and part of them will become obvious from the description, or be understood by implementing the embodiments of the present invention. The objectives and other advantages of the present invention can be achieved and obtained through the structures specifically pointed out in the written description, claims, and drawings. Description of the Drawings

[0012] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for use in the embodiments. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.

[0013] Figure 1 Schematic diagram of the process of the two-way network access authentication method for the board card described in the embodiments of the present invention;

[0014] Figure 2 Schematic diagram of the structure of the two-way network access authentication device for the board card described in the embodiments of the present invention;

[0015] Figure 3 Schematic diagram of the structure of the two-way network access authentication board card described in the embodiments of the present invention. Specific embodiments

[0016] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Usually, the components of the embodiments of the present invention described and shown in the accompanying drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the claimed present invention, but only represents the selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.

[0017] It should be noted that: similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present invention, terms such as "first" and "second" are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.

[0018] Embodiment 1:

[0019] This embodiment provides a two-way network access authentication method for the board card.

[0020] See Figure 1 , the figure shows that this method includes step S100, step S200, and step S300.

[0021] S100. Extract the first information from the non-volatile memory. The first information includes serial number information, hardware drivers, and service function information. The service function information includes the executable function codes of the board, and the serial number information includes the unique serial number corresponding to the board.

[0022] S200. Send the second information. The second information includes the serial number information, the version information in the service function information and the hardware drivers. The second information is used to trigger the control unit to perform two-way time verification on the network access legality of the board side. If the verification is successful, a service loading frame is sent.

[0023] S300. Obtain and verify whether the service loading frame is correct. If the service loading frame is correct, obtain the function code, store the function code in the dynamic random access memory, and perform service calculations according to the function code in the dynamic random access memory.

[0024] In this method, by standardizing the design of the board, that is, this method is used for standardizing the design of the board. The so-called standardization design mentioned here refers to the board with a unified board hardware architecture. Through the above design, when the entire system requires corresponding functions, different functions can be implemented on limited hardware according to different usage scenarios, improving the environmental adaptability of the system; software codes for implementing the same function can also be loaded simultaneously on multiple board hardwares, and multiple boards work simultaneously to improve the computing power of the system; in addition, when a certain board fails, this function can be implemented on another board by loading software codes, improving the reliability of the system.

[0025] At the same time, when the information processing system is started, the board starts the hardware driver and service loading function from the non-volatile memory, and the control unit can communicate with the board for network communication and service loading. The control unit issues the selected function code to the specified board, and the board stores the code in the dynamic random access memory and executes the function service program. Since the non-volatile memory of the general computing board does not need to store the specific codes for completing the functions of the dedicated board, only the hardware driver and service loading function are required, so there is no information leakage before the board is transported and used, ensuring the security of business data; after the board is powered on, the function code needs to be issued by the control unit network, and all application services are centrally and uniformly managed by the control unit, making data control and management more convenient; after the board completes the calculation, the data in the dynamic random access memory will be automatically cleared when the power is off, so the risk of information leakage is also reduced.

[0026] Further, in some specific embodiments, step S200 further includes step S210, step S220, and step S230.

[0027] S210. Generate a first verification code based on the serial number information.

[0028] S220. Call the first private key to encrypt the first verification code, number information, service function information, version information, and the first moment to generate the second information, where the first moment is the generation moment of the second information.

[0029] S230. Send the second information according to the predetermined sending time, where the predetermined sending time is the time after accumulating the first moment and the first preset time length. The second information is used to trigger the control unit to call the first public key to decrypt the second information to obtain the decrypted number information, the first verification code, and the first moment. The decrypted number information is used to trigger the control unit to encrypt the decrypted number information to obtain the second verification code. The second verification code is used to trigger the control unit to determine that if the second verification code is the same as the first verification code and the difference between the first moment and the second information reception time is within the first allowable range, the network access of the board is recorded as legal.

[0030] In the above steps, by verifying the identity of the board card bidirectionally, the possibility of illegal board cards hijacking code information at any stage is eliminated, protecting the security of the function code. It should be noted that in this application, the first private key and the first public key are a pair of keys, and the second private key and the second public key are a pair of keys. Among them, in this embodiment, the bidirectional verification includes the first layer of verification using the first private key and the first public key. However, considering the possibility of leakage of the first private key and the first public key, the first moment is added as an additional authentication verification in the second information in this method. In the method of implementing the authentication verification, by sending the second information after a preset time period, the control unit not only needs to check the first verification code after decrypting the second information, but also needs to determine whether the time difference of the reception time of the second information is within the first allowable range. Only when both pieces of information meet the requirements, the network access request of the board card is recorded as legal. Among them, during the transmission of information, the sending time is used as the hidden verification direction. Even if the first public key and the first private key are leaked, the control unit can correctly identify the illegally inserted board card. It should be noted that in this application, the first preset time length can be 1s, and the first allowable range is 1s - 1.1s. Those skilled in the art can also select other time lengths and corresponding first allowable ranges, and no specific limitations are made in this application.

[0031] At the same time, in order to improve the security of information, there is a third layer of verification in this method. Specifically, step S200 further includes steps S240, S250, S260, and S270.

[0032] S240. The legal network access of the board card is used to trigger the control unit to generate a first response verification according to the number information. The first response verification is used to trigger the control unit to generate and send a response feedback according to the first response verification, the predetermined response time, and the preset second private key. The predetermined response time is the time after accumulating the current moment and the second preset time length.

[0033] S250. Receive and decrypt the response feedback according to the preset second public key to obtain the first response verification and the response sending time.

[0034] S260. Generate a verification string according to the number information.

[0035] S270. If the verification string is consistent with the first response verification, and the predetermined response time and the response feedback reception time are less than the second threshold, then feedback to the control center to confirm network access.

[0036] Furthermore, step S240 includes step S241 and step S242.

[0037] S241. Multiply each character in the number information by the first preset function respectively to calculate the first calculated value corresponding to each character.

[0038] S242. Combine and splice the first calculated values according to the order of each character in the number information to obtain the first response verification.

[0039] Step S260 includes step S261 and step S262.

[0040] S261. Multiply each character in the number information by the second preset function respectively to calculate the second calculated value corresponding to each character. The second preset function and the first preset function are conjugate functions.

[0041] It should be noted that in this application, the first preset function can be a sine function, and the second preset function can be a cosine function. As long as the first preset function and the second preset function are conjugate, no specific limitation is made in this application.

[0042] S262. Combine and splice the calculated values according to the order of each character in the number information to obtain the verification string.

[0043] Step S270 includes step S271 and step S272.

[0044] S271. Extract at least two maximum or minimum value characters and the corresponding positions of each maximum or minimum value character in the verification string and the first response verification respectively. The maximum or minimum value character is the character with the maximum value or the minimum value.

[0045] It should be noted that in the method, the maximum or minimum value character is the maximum or minimum value. For example, for a string of data 123456789, that is, extract the minimum character 1 at the 1st position and the maximum character 9 at the 9th position. For 511548998, this kind of data will also extract the minimum character 1 at the 2nd and 3rd positions and the maximum character 9 at the 7th and 8th positions. Similarly, for the verification string containing English characters, the above extraction method is also used, which will not be elaborated in this application.

[0046] S272. If the verification string is the same as both the maximum and minimum characters and their corresponding positions in the first response verification, then the verification string is consistent with the first response verification.

[0047] It should be noted that in this step, it is necessary to verify both the maximum value itself and the position where the maximum value is located, as well as the minimum value itself and the position where the minimum value is located. In this method, through the above method, the integrity of the data can be verified to ensure the correctness of the information.

[0048] In some specific embodiments, step S210 includes step S211, step S212, and step S213 to achieve the purpose of generating the first verification code.

[0049] S211. Obtain the vector values corresponding to each character in the number information from the preset vector table.

[0050] S212. Combine and splice the vector values according to the order of each character in the number information to obtain a mapping vector.

[0051] S213. Perform a linear transformation on the mapping vector based on the preset matrix to obtain a transformation vector, and record the transformation vector as the first verification code.

[0052] In some specific embodiments, this method further includes step S400, step S500, and step S600.

[0053] S400. Perform an exclusive OR operation on the number information and the first agreed-upon moment to obtain a first calculation result, where the first agreed-upon moment is calculated based on the receiving moment.

[0054] S500. Call the first private key to encrypt the first calculation result and the operation result to obtain an encrypted calculation result, where the operation result is the result after service calculation.

[0055] S600. Send the encrypted calculation result to the control unit. The encrypted calculation result is used to trigger the control unit to calculate the agreed-upon time based on the second information sending time and call the first public key to decrypt the encrypted calculation result to obtain the decrypted first calculation result and the operation result. The agreed-upon time is used to trigger the control unit to perform an exclusive OR operation on the agreed-upon time and the number information to obtain a second calculation result. The second calculation result is used to trigger the control unit to perform a CRC check on the first calculation result and the second calculation result. If the CRC check passes, it is determined that the decrypted operation result is legal. If the CRC check fails, the received encrypted calculation result is discarded.

[0056] In this method, for the legally passed board cards, messages are sent to the qualified board cards for verification, reducing the resource occupation from the control unit to the board cards and releasing the channel resources while ensuring communication security.

[0057] In this application, the calculation method of the agreed time includes:

[0058] Calculate the transmission delay based on the first moment in the second information and the second information reception time, where the first moment is the generation moment of the second information.

[0059] Obtain the agreed time based on the reception moment of the encryption calculation result and the transmission delay.

[0060] Embodiment 2:

[0061] As Figure 2 shown, this embodiment provides a board card two-way network access authentication device, and the device includes:

[0062] The first extraction unit 1 is used to extract the first information in the non-volatile memory. The first information includes number information, hardware driver, and service function information. The service function information includes the board card executable function code, and the number information includes the unique number corresponding to the board card.

[0063] The first sending unit 2 is used to send the second information. The second information includes the number information, the version information in the service function information and the hardware driver. The second information is used to trigger the control unit to perform two-way time verification on the network access legality of the board card end. If the verification is successful, a service loading frame is sent.

[0064] The first verification unit 3 is used to obtain and verify whether the service loading frame is correct. If the service loading frame is correct, obtain the function code, store the function code in the dynamic random access memory, and perform service calculation according to the function code in the dynamic random access memory.

[0065] In some other specific embodiments, the first sending unit 2 includes:

[0066] The first encryption unit 21 is used to generate the first verification code based on the number information.

[0067] The second encryption unit 22 is used to call the first private key to encrypt the first verification code, the number information, the service function information, the version information, and the first moment to generate the second information, where the first moment is the generation moment of the second information.

[0068] A second sending unit 23, configured to send second information according to a predetermined sending time, where the predetermined sending time is the time after accumulating a first moment and a first preset time length, and the second information is used to trigger a control unit to decrypt the second information by using a first public key to obtain decrypted number information, a first verification code, and a first moment. The decrypted number information is used to trigger the control unit to encrypt the decrypted number information to obtain a second verification code, and the second verification code is used to trigger the control unit to determine that if the second verification code is the same as the first verification code and the difference between the first moment and the second information receiving time is within a first allowable range, then record that the board card is legally networked.

[0069] In some other specific embodiments, the first sending unit 2 further includes:

[0070] The second sending unit 23 is further configured to trigger the control unit to generate a first response verification according to the number information when the board card is legally networked. The first response verification is used to trigger the control unit to generate and send a response feedback according to the first response verification, a predetermined response time, and a preset second private key. The predetermined response time is the time after accumulating the current moment and a second preset time length.

[0071] A first decryption unit 24, configured to receive and decrypt the response feedback by using a preset second public key to obtain a first response verification and a response sending time.

[0072] A third encryption unit 25, configured to generate a verification string according to the number information.

[0073] A first logic unit 26, configured to, if the verification string is consistent with the first response verification and the predetermined response time is less than a second threshold with respect to the response feedback receiving time, then feedback confirmation of network access to a control center.

[0074] In some other specific embodiments, the second sending unit 23 further includes:

[0075] A first calculation unit 231, configured to multiply each character in the number information by a first preset function respectively to calculate a first calculated value corresponding to each character.

[0076] A first splicing unit 232, configured to merge and splice the first calculated values in the order of each character in the number information to obtain a first response verification.

[0077] The third encryption unit 25 includes:

[0078] A second calculation unit 251, configured to multiply each character in the number information by a second preset function respectively to calculate a second calculated value corresponding to each character. The second preset function and the first preset function are conjugate functions.

[0079] A second splicing unit 252, configured to merge and splice the calculated values in sequence according to each character in the number information to obtain a verification string.

[0080] A first logic unit 26 includes:

[0081] A second extraction unit 261, configured to respectively extract at least two maximum or minimum value characters and the corresponding positions of each maximum or minimum value character in the verification string and the first response verification, where the maximum or minimum value character is the character with the maximum value or the minimum value.

[0082] A first sub-logic unit 262, configured to verify that the verification string and the first response verification are consistent if the maximum or minimum value characters and the corresponding positions of the maximum or minimum value characters in the verification string and the first response verification are the same.

[0083] In some other specific embodiments, the first encryption unit 21 further includes:

[0084] A first acquisition unit 211, configured to acquire the vector value corresponding to each character in the number information from a preset vector table.

[0085] A third splicing unit 212, configured to merge and splice the vector values in sequence according to each character in the number information to obtain a mapping vector.

[0086] A transformation unit 213, configured to perform a linear transformation on the mapping vector based on a preset matrix to obtain a transformation vector, and record the transformation vector as the first verification code.

[0087] In some other specific embodiments, the device further includes:

[0088] A third calculation unit 4, configured to perform an exclusive OR operation on the number information and a first agreed time to obtain a first calculation result, where the first agreed time is obtained by accepting the time calculation.

[0089] A fourth encryption unit 5, configured to call a first private key to encrypt the first calculation result and the operation result to obtain an encrypted calculation result, where the operation result is the result after service calculation.

[0090] A third sending unit 6, configured to send the encrypted calculation result to a control unit, where the encrypted calculation result is used to trigger the control unit to calculate an agreed time according to a second information sending time and call a first public key to decrypt the encrypted calculation result to obtain the decrypted first calculation result and the operation result. The agreed time is used to trigger the control unit to perform an exclusive OR operation on the agreed time and the number information to obtain a second calculation result. The second calculation result is used to trigger the control unit to perform a CRC check on the first calculation result and the second calculation result. If the CRC check passes, it is determined that the decrypted operation result is legal. If the CRC check fails, the received encrypted calculation result is discarded.

[0091] In some other specific embodiments, the third sending unit 6 further includes:

[0092] A fourth calculation unit 61, configured to calculate a transmission delay according to a first moment in the second information and a second information reception time, where the first moment is the generation moment of the second information.

[0093] A fifth calculation unit 62, configured to obtain a scheduled time according to a reception moment of an encryption calculation result and the transmission delay.

[0094] It should be noted that regarding the device in the above embodiments, the specific manners in which each module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated herein.

[0095] Embodiment 3:

[0096] Corresponding to the above method embodiment, in this embodiment, a board two-way network access authentication board is further provided. A board two-way network access authentication board described below can be correspondingly referred to the board two-way network access authentication method described above.

[0097] Figure 3 It is a block diagram of a board two-way network access authentication board 800 shown according to an exemplary embodiment. As Figure 3 shown, the board two-way network access authentication board 800 may include: a processor 801, a memory 802. The board two-way network access authentication board 800 may further include one or more of an I / O interface 804 and a communication component 805.

[0098] Among them, the processor 801 is used to control the overall operation of the board two-way network access authentication board 800 to complete all or part of the steps in the above board two-way network access authentication method. The memory 802 is used to store various types of data to support the operation of the board two-way network access authentication board 800. These data may include, for example, instructions for any application program or method operating on the board two-way network access authentication board 800, as well as application-related data, such as contact data, sent and received messages, pictures, audio, video, and so on. The memory 802 is implemented by a combination of volatile and non-volatile storage boards. The I / O interface 804 provides an interface between the processor 801 and other interface modules. The above other interface modules may be a keyboard, a mouse, buttons, etc. These buttons may be virtual buttons or physical buttons. The communication component 805 is used for the board two-way network access authentication board 800 to perform wired or wireless communication with other boards. Wireless communication, such as Wi-Fi, Bluetooth, Near Field Communication (NFC), 2G, 3G or 4G, or a combination of one or more of them. Accordingly, the communication component 805 may include: a Wi-Fi module, a Bluetooth module, an NFC module.

[0099] The above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.

Claims

1. A two-way network access authentication method for a board card, which is used for the board card side, characterized in that, it includes: Extract the first information in the non-volatile memory, where the first information includes serial number information, hardware drivers, and service function information. The service function information includes executable function codes of the board card, and the serial number information includes the unique serial number corresponding to the board card; Send the second information, where the second information includes the serial number information, the version information in the service function information and the hardware driver. The second information is used to trigger the control unit to verify the legality of the board card's network access. If the verification is successful, a service loading frame is sent; Obtain and verify whether the service loading frame is correct. If the service loading frame is correct, obtain the function code, store the function code in the dynamic random access memory, and perform service calculations according to the function code in the dynamic random access memory; Among them, the sending of the second information, where the second information includes the serial number information, the service function information and the version information in the hardware driver, and the second information is used to trigger the control unit to send a service loading frame, includes: Generate a first verification code based on the serial number information for encryption; Call the first private key to encrypt the first verification code, the serial number information, the service function information, the version information, and the first moment, where the first moment is the generation moment of the second information, to generate the second information; Send the second information according to the predetermined sending time, where the predetermined sending time is the time after the first moment is accumulated with the first preset time length. The second information is used to trigger the control unit to call the first public key to decrypt the second information to obtain the decrypted serial number information, the first verification code, and the first moment. The decrypted serial number information is used to trigger the control unit to encrypt the decrypted serial number information to obtain a second verification code. The second verification code is used to trigger the control unit to determine that if the second verification code is the same as the first verification code and the difference between the first moment and the second information reception time is within the first allowable range, the board card's network access is recorded as legal; The legal network access of the board card is used to trigger the control unit to generate a first response verification according to the serial number information. The first response verification is used to trigger the control unit to generate and send a response feedback according to the first response verification, the predetermined response time, and the preset second private key. The predetermined response time is the time after the current moment is accumulated with the second preset time length; Receive and decrypt the response feedback according to the preset second public key to obtain the first response verification and the predetermined response time; Generate a verification string according to the serial number information; If the verification string is consistent with the first response verification, and the predetermined response time is less than the second threshold value compared with the response feedback reception time, then feedback confirmation of network access to the control center.

2. The two-way network access authentication method for a board card according to claim 1, characterized in that , generating a first verification code based on the serial number information for encryption includes: Obtain the vector value corresponding to each character in the serial number information from the preset vector table; Merge and splice the vector values in sequence according to each character in the serial number information to obtain a mapping vector; Perform a linear transformation on the mapping vector based on a preset matrix to obtain a transformation vector, and denote the transformation vector as the first verification code.

3. The board card two-way network access authentication method according to claim 1, characterized in that , generating a verification string according to the number information, including: Multiplying each character in the number information by a second preset function respectively to calculate a second calculated value corresponding to each character, and the second preset function and the first preset function are conjugate functions; Combining and splicing the calculated values in the order of each character in the number information to obtain a verification string.

4. The board card two-way network access authentication method according to claim 1, characterized in that , the service calculation based on the function code in the dynamic random access memory, and then includes: Performing an exclusive OR operation on the number information and a first agreed-upon moment to obtain a first calculation result, and the first agreed-upon moment is calculated from the reception moment of the second information; Invoking a first private key to encrypt the first calculation result and the operation result to obtain an encrypted calculation result, and the operation result is the result after service calculation; Sending the encrypted calculation result to the control unit, and the encrypted calculation result is used to trigger the control unit to calculate an agreed-upon time according to the second information sending time and invoke a first public key to decrypt the encrypted calculation result to obtain the decrypted first calculation result and the operation result, and the agreed-upon time is used to trigger the control unit to perform an exclusive OR operation on the agreed-upon time and the number information to obtain a second calculation result, and the second calculation result is used to trigger the control unit to perform a CRC check on the first calculation result and the second calculation result. If the CRC check passes, it is determined that the decrypted operation result is legal. If the CRC check fails, the received encrypted calculation result is discarded.

5. A board card two-way network access authentication device, characterized in that , including: A first extraction unit for extracting first information in a non-volatile memory, the first information including number information, a hardware driver, and service function information, the service function information including executable function codes of the board card, and the number information including a unique number corresponding to the board card; A first sending unit for sending second information, the second information including version information in the number information, the service function information, and the hardware driver, and the second information is used to trigger the control unit to verify the legality of network access at the board card end. If the verification is successful, a service loading frame is sent; A first verification unit for obtaining and verifying whether the service loading frame is correct. If the service loading frame is correct, obtaining a function code, storing the function code in a dynamic random access memory, and performing a service calculation according to the function code in the dynamic random access memory; Among them, the first sending unit includes: A first encryption unit for encrypting based on the number information to generate a first verification code; A second encryption unit for invoking a first private key to encrypt the first verification code, the number information, the service function information, the version information, and a first moment to generate second information, and the first moment is the generation moment of the second information; A second sending unit, configured to send the second information according to a predetermined sending time, where the predetermined sending time is a time obtained by accumulating a first moment and a first preset time length, and the second information is used to trigger the control unit to call a first public key to decrypt the second information to obtain the decrypted number information, a first verification code, and the first moment. The decrypted number information is used to trigger the control unit to encrypt the decrypted number information to obtain a second verification code, and the second verification code is used to trigger the control unit to determine that if the second verification code is the same as the first verification code and the difference between the first moment and the second information reception time is within a first allowable range, then record that the board card's network access is legal; The second sending unit is further configured to, when the board card's network access is legal, trigger the control unit to generate a first response verification according to the number information, and the first response verification is used to trigger the control unit to generate and send a response feedback according to the first response verification, a predetermined response time, and a preset second private key. The predetermined response time is a time obtained by accumulating the current moment and a second preset time length; A first decryption unit, configured to receive and decrypt the response feedback according to a preset second public key to obtain a first response verification and a predetermined response time; A third encryption unit, configured to generate a verification string according to the number information; A first logic unit, configured to, if the verification string is consistent with the first response verification and the predetermined response time is less than a second threshold with respect to the response feedback reception time, then feedback confirmation of network access to the control center.

6. The board card two-way network access authentication device according to claim 5, wherein, the first encryption unit includes: A first obtaining unit, configured to obtain a vector value corresponding to each character in the number information from a preset vector table; A third splicing unit, configured to sequentially merge and splice the vector values according to each character in the number information to obtain a mapping vector; A transformation unit, configured to perform a linear transformation on the mapping vector based on a preset matrix to obtain a transformation vector, and record the transformation vector as the first verification code.

7. The board card two-way network access authentication device according to claim 5, wherein, the third encryption unit includes: A second calculation unit, configured to multiply each character in the number information by a second preset function respectively to calculate a second calculated value corresponding to each character. The second preset function and the first preset function are conjugate functions; A second splicing unit, configured to sequentially merge and splice the calculated values according to each character in the number information to obtain a verification string.

8. A board card, wherein, it includes: A memory, configured to store a computer program; A processor, configured to implement the steps of the board card two-way network access authentication method according to any one of claims 1 to 4 when executing the computer program.

Citation Information

Patent Citations

  • Board card network access verification method and device and board card control center

    CN114244620A