A device authentication generation method and device
By generating equipment manufacturer certificates and equipment certificates by the equipment manufacturer, and combining the equipment product's device identifier and key, the network security issues caused by the replacement of pluggable devices are resolved, and the legality and security of the equipment products are certified.
Patent Information
- Application Number
- CN202211240294.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-11
- Publication Date
- 2025-10-21
- Estimated Expiration
- 2042-10-11
AI Technical Summary
Existing pluggable devices may be unplugged and replaced, causing security issues in the communication network.
By generating equipment manufacturer certificates and equipment certificates through equipment manufacturers, and combining the equipment product's equipment identification and key, equipment authentication is carried out to ensure the legality and security of equipment products.
It enables the certification of the legality and security of equipment products, ensuring the overall security of the communication network.
Smart Images

Figure CN115643022B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technology, and in particular to a device authentication generation method and a device product. Background Art
[0002] In optical transmission rack systems, with the development of data centers, pluggable modules (such as those in SFP, QSFP, QSFP-DD, and OSFP form factors) are increasingly being used. Due to the pluggable nature of these modules, they can be removed and replaced. If a pluggable device designed to steal confidential information or disrupt communications were inserted into the rack to replace these modules, it could lead to serious security issues for the entire communications network.
[0003] In view of this, overcoming the defects of the prior art is an urgent problem to be solved in this technical field. Summary of the Invention
[0004] The technical problem to be solved by the present invention is that existing pluggable devices may be unplugged and replaced, resulting in safety problems.
[0005] In a first aspect, the present invention provides a method for generating a device authentication, which involves at least a device manufacturer, a consumer user, and a device product, wherein the device product is produced by the device manufacturer, and the authentication generation includes:
[0006] The device manufacturer obtains a device vendor certificate issued by a consumer user; wherein the device vendor certificate is jointly generated by a first certificate subject and a first certificate signature, wherein the first certificate subject is composed of the device vendor identifier and the device vendor public key in the device vendor key pair, and the first certificate signature is obtained by signing the first certificate subject using the consumer user's user certificate;
[0007] The device manufacturer also obtains the device identification of the device product, forms a second certificate subject with the device vendor certificate, the device identification of the device product, and the device public key in the device key pair, and uses the device vendor private key in the device vendor key pair to sign the second certificate subject to obtain a second certificate signature. The second certificate subject and the second certificate signature jointly generate a device certificate;
[0008] The device private key in the device certificate and device key pair is burned into the storage area of the device product; the user certificate is transmitted to the host by the consumer user so that the host that installs the device product can complete the authentication process of the device product.
[0009] Preferably, the process of completing the authentication of the device product by the host computer that installs the device product specifically includes:
[0010] The host obtains the device vendor certificate from the device certificate, obtains the first certificate signature from the device vendor certificate, and verifies the validity of the first certificate signature using the user certificate;
[0011] After verifying the validity of the first certificate signature, obtaining the device manufacturer's public key in the device manufacturer key pair from the device manufacturer certificate, obtaining the second certificate signature from the device certificate, and verifying the validity of the second certificate signature using the device manufacturer's public key;
[0012] After verifying the validity of the signature of the second certificate, the device public key in the device key is obtained from the device certificate, and it is verified whether the device public key matches the device private key in the storage area of the device product. If it is verified that the device public key matches the device private key, the authentication process of the device product is completed.
[0013] Preferably, the verifying whether the device public key matches the device private key in the storage area of the device product specifically includes:
[0014] The host sends the generated random number to the device product, and obtains an encryption result obtained by the device product encrypting the random number according to the device private key;
[0015] The host decrypts the encryption result using the device public key to obtain a decryption result, and determines whether the decryption result is consistent with the random number;
[0016] If the decryption result is consistent with the random number, it is verified that the device public key matches the device private key.
[0017] Preferably, the using the user certificate to verify the validity of the first certificate signature specifically includes:
[0018] The host obtains the first certificate subject in the device vendor certificate, and uses the user certificate to issue the first certificate subject to obtain an issuance result;
[0019] Determine whether the issuance result is consistent with the first certificate signature; if the issuance result is consistent with the first certificate signature, verify that the validity of the first certificate signature is passed.
[0020] Preferably, the device product includes at least one of a pluggable optical module device, an on-chip storage space of a chip, and other pluggable devices suitable for a blade server; wherein, the pluggable optical module device includes at least one of an optical module with SFP package, QSFP package, QSFP-DD package, and OSFP package.
[0021] In a second aspect, the present invention further provides a method for generating a device authentication, which involves at least a device manufacturer, a consumer user, and a device product, wherein the device product is produced by the device manufacturer, and the authentication generation includes:
[0022] The device manufacturer obtains a device vendor certificate issued by a consumer user; wherein the device vendor certificate is jointly generated by a first certificate subject and a first certificate signature, wherein the first certificate subject is composed of the device vendor identifier and the device vendor public key in the device vendor key pair, and the first certificate signature is obtained by signing the first certificate subject using the consumer user's user certificate;
[0023] The device manufacturer also obtains the device identification of the device product, uses the device identification of the device product and the device public key in the device key pair to form a second certificate subject, and uses the device manufacturer's private key in the device manufacturer's key pair to sign the second certificate subject to obtain a second certificate signature. The second certificate subject and the second certificate signature jointly generate a device certificate;
[0024] The device private key in the device certificate and device key pair is burned into the storage area of the device product; the user certificate and device vendor certificate are transmitted to the host by the consumer user so that the host that installs the device product can complete the authentication process of the device product.
[0025] Preferably, the process of completing the authentication of the device product by the host computer that installs the device product specifically includes:
[0026] The host obtains the first certificate signature from the device vendor certificate and verifies the validity of the first certificate signature using the user certificate;
[0027] After verifying the validity of the first certificate signature, obtaining the device manufacturer's public key in the device manufacturer key pair from the device manufacturer certificate, obtaining the second certificate signature from the device certificate, and verifying the validity of the second certificate signature using the device manufacturer's public key;
[0028] After verifying the validity of the signature of the second certificate, the device public key in the device key is obtained from the device certificate, and it is verified whether the device public key matches the device private key in the storage area of the device product. If it is verified that the device public key matches the device private key, the authentication process of the device product is completed.
[0029] Preferably, the verifying whether the device public key matches the device private key in the storage area of the device product specifically includes:
[0030] The host sends the generated random number to the device product, and obtains an encryption result obtained by the device product encrypting the random number according to the device private key;
[0031] The host decrypts the encryption result using the device public key to obtain a decryption result, and determines whether the decryption result is consistent with the random number;
[0032] If the decryption result is consistent with the random number, it is verified that the device public key matches the device private key.
[0033] Preferably, the using the user certificate to verify the validity of the first certificate signature specifically includes:
[0034] The host obtains the first certificate subject in the device vendor certificate, and uses the user certificate to issue the first certificate subject to obtain an issuance result;
[0035] Determine whether the issuance result is consistent with the first certificate signature; if the issuance result is consistent with the first certificate signature, verify that the validity of the first certificate signature is passed.
[0036] In a third aspect, the present invention also provides a device product, which is produced by a device manufacturer, and the device private key in the device certificate and device key pair is burned in the storage area of the device product. The device certificate and device key pair are generated based on the device authentication generation method described in the first aspect or the second aspect.
[0037] In a fourth aspect, the present invention further provides a device authentication generation apparatus for implementing the device authentication generation method described in the first aspect or the second aspect, the apparatus comprising:
[0038] At least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the processor to execute the device authentication generation method described in the first aspect or the second aspect.
[0039] In a fourth aspect, the present invention further provides a non-volatile computer storage medium, wherein the computer storage medium stores computer-executable instructions, which are executed by one or more processors to complete the device authentication generation method described in the first aspect or the second aspect.
[0040] The present invention generates a vendor certificate and a device certificate through interaction among the consumer user, the device vendor, and the device product. When the device product is inserted into the host, the device product is authenticated and tampered or illegal device products are identified, thereby ensuring the legitimacy and security of the device product and the overall security of the communication network. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments of the present invention. Obviously, the drawings described below are only some embodiments of the present invention. Those skilled in the art can also derive other drawings based on these drawings without inventive effort.
[0042] Figure 1 This is a flow chart of a device authentication generation method provided by an embodiment of the present invention;
[0043] Figure 2 Schematic diagram of a device authentication generation method provided by an embodiment of the present invention;
[0044] Figure 3 This is a schematic diagram of the structure of a device vendor certificate provided by an embodiment of the present invention;
[0045] Figure 4 This is a schematic diagram of the structure of a device certificate provided by an embodiment of the present invention;
[0046] Figure 5 This is a flow chart of a device authentication generation method provided by an embodiment of the present invention;
[0047] Figure 6 Schematic diagram of a device authentication generation method provided by an embodiment of the present invention;
[0048] Figure 7 This is a flow chart of a device authentication generation method provided by an embodiment of the present invention;
[0049] Figure 8 This is a flow chart of a device authentication generation method provided by an embodiment of the present invention;
[0050] Figure 9 This is a flow chart of a device authentication generation method provided by an embodiment of the present invention;
[0051] Figure 10 This is a schematic diagram of the structure of a device certificate provided by an embodiment of the present invention;
[0052] Figure 11 This is a flow chart of a device authentication generation method provided by an embodiment of the present invention;
[0053] Figure 12 This is a flow chart of a device authentication generation method provided by an embodiment of the present invention;
[0054] Figure 13 This is a flow chart of a device authentication generation method provided by an embodiment of the present invention;
[0055] Figure 14This is a flow chart of a device authentication generation method provided by an embodiment of the present invention;
[0056] Figure 15 This is a flow chart of a device authentication generation method provided by an embodiment of the present invention;
[0057] Figure 16 is a schematic diagram of a storage area in a device product provided by an embodiment of the present invention;
[0058] Figure 17 This is a schematic diagram of the architecture of a device authentication generation apparatus provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0059] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0060] In the description of the present invention, the terms "inside", "outside", "longitudinal", "lateral", "upper", "lower", "top", "bottom", etc. indicate orientations or positional relationships based on the orientations or positional relationships shown in the accompanying drawings. They are only for the convenience of describing the present invention and do not require that the present invention must be constructed and operated in a specific orientation. Therefore, they should not be understood as limitations on the present invention.
[0061] In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.
[0062] Embodiment 1:
[0063] Embodiment 1 of the present invention provides a device authentication generation method, which involves at least a device manufacturer, a consumer user, and a device product, wherein the device product is produced by the device manufacturer, such as Figure 1 and Figure 2 As shown, the authentication generation includes:
[0064] In step 201, the device manufacturer obtains a device vendor certificate issued by a consumer user; wherein, the device vendor certificate is generated by a first certificate subject and a first certificate signature, wherein the first certificate subject is composed of a device vendor identifier and a device vendor public key in a device vendor key pair, and the first certificate signature is obtained by signing the first certificate subject with the user certificate of the consumer user; the generated device vendor certificate is as follows: Figure 3 shown.
[0065] There may be one or more device manufacturers, and the device vendor identifier may be the manufacturer information of the device manufacturer. There may be one or more device products. The authentication generation process of this embodiment mainly involves three parties, including consumer users, device manufacturers, and device products. One consumer user corresponds to one or more user certificates, and one device manufacturer corresponds to one or more device vendor key pairs. The device vendor key pair is pre-generated by the device manufacturer using an asymmetric encryption algorithm. There are many asymmetric encryption algorithms, including RSA, ECDSA, ECC, AES, and SM2.
[0066] The device product includes at least one of a pluggable optical module device, an on-chip storage space of a chip, and other pluggable devices suitable for a blade server; wherein, the pluggable optical module device includes at least one of an optical module with SFP package, QSFP package, QSFP-DD package, and OSFP package.
[0067] The consumer user generates a user certificate that does not need to be issued or is issued by himself. There are many ways to generate the user certificate, for example:
[0068] The first method uses any custom string as the user certificate.
[0069] In the second method, the consumer user generates a user key pair, uses the user identifier and the user public key in the user key pair to form the certificate body of the user certificate, and uses the user private key in the user key pair to sign the certificate body of the user certificate to obtain a certificate signature. The certificate body and certificate signature of the user certificate together constitute the user certificate.
[0070] The user certificate is the most fundamental basis for verifying the validity of all vendor certificates and device certificates.
[0071] Each device manufacturer is associated with one or more vendor certificates. The manufacturer sends its vendor ID and public key (the first certificate subject) to the consumer and requests a vendor certificate. The consumer verifies the manufacturer is legitimate based on the vendor ID and generates a vendor certificate. If the manufacturer is not legitimate, no vendor certificate is generated.
[0072] The first certificate signature is obtained by signing the first certificate subject using the consumer's user certificate. An optional implementation includes calculating a digest of the first certificate subject and encrypting the calculated digest using the user's private key to obtain the first certificate signature. There are various methods for calculating digests, including MD4, MD5, SHA-1, SHA-256, SHA-384, and SHA-512.
[0073] In step 202, the device manufacturer also obtains the device identification of the device product, and uses the device manufacturer certificate, the device identification of the device product and the device public key in the device key pair to form a second certificate body, and uses the device manufacturer private key in the device manufacturer key pair to issue the second certificate body to obtain a second certificate signature, and the second certificate body and the second certificate signature jointly generate a device certificate; the generated device certificate is as follows: Figure 4 shown.
[0074] Each device product is associated with a device certificate, generated by the device manufacturer that manufactures the device product. Each device product is also associated with a device key pair, pre-generated by the device manufacturer. Each device has a unique device identifier, which is obtained by the device manufacturer from the device.
[0075] After the device manufacturer obtains the device identification of the device product, the device manufacturer also verifies whether the device product is a legal device product based on the device identification. If it is legal, a device certificate is generated; otherwise, no device certificate is generated.
[0076] In step 203, the device private key in the device certificate and device key pair is burned into the storage area of the device product; the user certificate is transmitted to the host by the consumer user so that the host that installs the device product can complete the authentication process of the device product.
[0077] In this embodiment, the consumer user can be understood as the manager of the device production authentication process, and has absolute authority to manage whether the device product is legal and whether the device manufacturer is legal. For example, the consumer user can be the user, seller or manufacturer of the host, and the consumer user also acts as a principal to entrust the device manufacturer to manufacture device products that can be used by the host. The device manufacturer's authority to manufacture device products is controlled by the consumer user. If the consumer user does not provide the device manufacturer with a valid device manufacturer certificate, the device manufacturer cannot generate a valid device certificate and thus cannot generate a valid device. Or if the consumer user does not transmit a valid user certificate to the host, the device product cannot be effectively authenticated and the device cannot be installed on the host.
[0078] This embodiment generates a corresponding device certificate for the device product through interaction between the consumer user, the device manufacturer, and the device product. When the device product is inserted into the host, the device certificate can be used to authenticate the device product and identify tampered or illegal device products, thereby ensuring the legitimacy and security of the device product and the overall security of the communication network.
[0079] Based on the device product in the above embodiment, this embodiment also provides a specific implementation method for how to authenticate the device product, that is, the host that installs the device product completes the authentication process of the device product, such as Figure 5 and Figure 6 As shown, specifically including:
[0080] In step 301, the host obtains the device vendor certificate from the device certificate, obtains the first certificate signature from the device vendor certificate, and verifies the validity of the first certificate signature using the user certificate;
[0081] In step 302, after verifying the validity of the first certificate signature, the device manufacturer public key in the device manufacturer key pair is obtained from the device manufacturer certificate, and the second certificate signature is obtained from the device certificate, and the validity of the second certificate signature is verified using the device manufacturer public key.
[0082] In step 303, after verifying the validity of the signature of the second certificate, the device public key in the device key is obtained from the device certificate, and it is verified whether the device public key matches the device private key in the storage area of the device product. If it is verified that the device public key matches the device private key, the authentication process of the device product is completed.
[0083] The verification of the validity of the first certificate signature is actually verification of whether the equipment vendor certificate is valid, and the verification of the validity of the second certificate signature is actually verification of whether the equipment certificate is valid.
[0084] The host and the device product match each other. For example, when the device product is a pluggable optical module, the host may be an OLT device.
[0085] Here, an optional implementation method of using a user certificate to verify the validity of the first certificate signature is also provided, such as Figure 7 As shown, specifically including:
[0086] In step 401, the host obtains the first certificate subject in the device vendor certificate, and uses the user certificate to sign the first certificate subject to obtain a signing result.
[0087] In step 402, it is determined whether the issuance result is consistent with the first certificate signature. If the issuance result is consistent with the first certificate signature, the validity of the first certificate signature is verified to be passed.
[0088] In the above-mentioned method 1 for generating the user certificate or the method 2 for generating the user certificate, this embodiment can be applied to the process of authenticating the validity of the signature of the first certificate.
[0089] Here, another optional implementation method is provided for the second method of generating the user certificate, which specifically includes:
[0090] The host obtains the first certificate signature in the device vendor certificate and the user public key in the user certificate, and uses the user public key to decrypt the first certificate signature to obtain a decryption result.
[0091] The host further obtains a first certificate subject in the device vendor certificate, and calculates a digest of the first certificate subject to obtain a digest result.
[0092] Determine whether the digest result is consistent with the decryption result; if so, verify that the validity of the first certificate signature is passed.
[0093] After verifying the validity of the first certificate signature and the second certificate signature, it is necessary to verify the validity of the device key pair. This embodiment provides an optional implementation method, such as Figure 8 As shown, the verification of whether the device public key matches the device private key in the storage area of the device product specifically includes:
[0094] In step 501, the host sends a generated random number to the device product, and obtains an encryption result obtained by the device product encrypting the random number according to the device private key.
[0095] In step 502, the host decrypts the encryption result using the device public key to obtain a decryption result, and determines whether the decryption result is consistent with the random number.
[0096] In step 503, if the decryption result is consistent with the random number, it is verified that the device public key matches the device private key.
[0097] Among them, as an optional implementation, in step 501, the host may send the generated random number to the device product or send the hash value of the random number. Correspondingly, in step 502, it is determined whether the decryption result is consistent with the hash value of the random number; in step 503, if the decryption result is consistent with the hash value of the random number, it is verified that the device public key matches the device private key.
[0098] The "first", "second" and "third" in this embodiment do not have any special limiting meanings. They are used for description only to facilitate the description of different individuals in a category of objects. They should not be interpreted as order or other aspects with special limiting meanings.
[0099] Example 2:
[0100] Compared to the implementation method of directly placing the device vendor certificate into the device certificate in Example 1, this embodiment also provides another implementation method, that is, the device vendor certificate is not placed into the device certificate, but the consumer user transmits the device vendor certificate to the host.
[0101] The present embodiment provides a device authentication generation method, which at least involves a device manufacturer, a consumer user, and a device product, wherein the device product is produced by the device manufacturer, such as Figure 9 As shown, the authentication generation includes:
[0102] In step 601, the device manufacturer obtains a device vendor certificate issued by a consumer user; wherein, the device vendor certificate is jointly generated by a first certificate subject and a first certificate signature, the first certificate subject is composed of a device vendor identifier and a device vendor public key in a device vendor key pair, and the first certificate signature is obtained by issuing the first certificate subject with the user certificate of the consumer user.
[0103] In step 602, the device manufacturer also obtains the device identification of the device product, and uses the device identification of the device product and the device public key in the device key pair to form a second certificate subject, and uses the device manufacturer private key in the device manufacturer key pair to issue the second certificate subject to obtain a second certificate signature, and the second certificate subject and the second certificate signature jointly generate a device certificate; the generated device certificate is as follows: Figure 10 shown.
[0104] In step 603, the device private key in the device certificate and device key pair is burned into the storage area of the device product; the user certificate and device vendor certificate are transmitted to the host by the consumer user so that the host that installs the device product can complete the authentication process of the device product.
[0105] Among them, the device product can be a pluggable optical module device, on-chip storage space of a chip, or other pluggable devices suitable for blade servers; wherein, the pluggable optical module device includes at least one of SFP packaged, QSFP packaged, QSFP-DD packaged and OSFP packaged optical modules.
[0106] The process of generating the device vendor certificate and the user certificate is based on the same concept as in Example 1 and will not be described in detail here.
[0107] However, what is different from Example 1 is that when generating a device certificate, this embodiment uses the device public key and device identification as the second certificate subject, and does not place the device vendor certificate in it. The device vendor's private key is then used to sign the second certificate subject to obtain a second certificate signature, thereby generating a device certificate.
[0108] At the same time, the device vendor certificate is transmitted from the consumer user to the host, which brings about a different authentication process.
[0109] The host computer that installs the device product completes the authentication process of the device product, such as Figure 11 As shown, specifically including:
[0110] In step 701, the host obtains a first certificate signature from the device vendor certificate and uses a user certificate to verify the validity of the first certificate signature.
[0111] In step 702, after verifying the validity of the first certificate signature, the device manufacturer public key in the device manufacturer key pair is obtained from the device manufacturer certificate, and the second certificate signature is obtained from the device certificate, and the validity of the second certificate signature is verified using the device manufacturer public key.
[0112] In step 703, after verifying the validity of the signature of the second certificate, the device public key in the device key is obtained from the device certificate, and it is verified whether the device public key matches the device private key in the storage area of the device product. If it is verified that the device public key matches the device private key, the authentication process of the device product is completed.
[0113] During authentication, since the device vendor certificate has been transmitted to the host by the consumer user in advance, the first certificate signature can be directly extracted from the device vendor certificate for subsequent authentication.
[0114] Verifying whether the device public key matches the device private key in the storage area of the device product specifically includes:
[0115] The host sends the generated random number to the device product, and obtains an encryption result obtained by the device product encrypting the random number according to the device private key.
[0116] The host decrypts the encryption result using the device public key to obtain a decryption result, and determines whether the decryption result is consistent with the random number.
[0117] If the decryption result is consistent with the random number, it is verified that the device public key matches the device private key.
[0118] Among them, as an optional implementation method, the host may send the generated random number to the device product or send the hash value of the random number. Correspondingly, when performing authentication, it is determined whether the decryption result is consistent with the hash value of the random number; if the decryption result is consistent with the hash value of the random number, it is verified that the device public key matches the device private key.
[0119] This embodiment provides an optional implementation method for verifying the validity of the first certificate signature, that is, using the user certificate to verify the validity of the first certificate signature, specifically including:
[0120] The host obtains the first certificate subject in the device vendor certificate, and uses the user certificate to sign the first certificate subject to obtain a signing result.
[0121] Determine whether the issuance result is consistent with the first certificate signature; if the issuance result is consistent with the first certificate signature, verify that the validity of the first certificate signature is passed.
[0122] In this embodiment, the device vendor certificate is not placed in the device certificate. Instead, the consumer user transmits the device vendor certificate to the host. Compared with Example 1, this embodiment is more suitable for scenarios where the transmission of the device vendor certificate between the consumer user and the host is completely secure. For example, when the consumer user is the manufacturer of the host, there is no need to place the device vendor certificate in the device certificate. Instead, the device vendor certificate is directly transmitted to the host. This simplifies the authentication generation process while ensuring the security of the authentication generation process.
[0123] Example 3:
[0124] The present invention is based on the methods described in Example 1 and Example 2, combined with specific application scenarios, and uses technical descriptions in related scenarios to illustrate the implementation process of the present invention in the characteristic scenarios.
[0125] Taking Example 1 as an example, if there is a pluggable optical module, this pluggable optical module is manufactured by equipment manufacturer V and is used to be inserted into the corresponding OLT device. The OLT device is manufactured by consumer user C. In this scenario, the device product is the pluggable optical module and the host is the OLT device.
[0126] The authentication production method in the pluggable optical module is as follows Figure 2 and Figure 12 As shown, specifically including:
[0127] In step 801, the device manufacturer V generates a device vendor key pair, including a device vendor public key V_Key_Pubic and a device vendor private key V_Key_Private.
[0128] In step 802 , the device manufacturer V sends the device manufacturer public key V_Key_Public and manufacturer information (equivalent to the device manufacturer identifier in embodiment 1) to the consumer user C to request a device manufacturer certificate.
[0129] In step 803, the consumer user C generates an unissued device vendor certificate for the device manufacturer V, which includes the device vendor public key and manufacturer information, and uses the user certificate to issue the device vendor certificate Cert_V.
[0130] In step 804 , the consumer user C sends the device vendor certificate Cert_V to the device manufacturer V.
[0131] In step 805, the device manufacturer V generates a device key pair for each pluggable optical module, including a device public key Dev_Key_Pubic and a device private key Dev_Key_Private.
[0132] In step 806, the device manufacturer V generates an unsigned device certificate for each pluggable optical module, which includes the device's unique security identifier (equivalent to the device identifier in Example 1), the device public key Dev_Key_Public, and the generated device vendor certificate Cert_V; and uses the device vendor's private key to sign it to obtain the issued device certificate Cert_Dev.
[0133] In step 807, the device manufacturer V burns the device private key Dev_Key_Private and the device certificate Cert_Dev into the device security storage area of the device product, such as into the read-only memory (ROM), and performs the authentication process of the pluggable optical module when the pluggable optical module is plugged in.
[0134] At the same time, consumer C transmits the user certificate to the OLT device for authentication of the pluggable optical module.
[0135] The pluggable optical module certification, such as Figure 13 As shown, specifically including:
[0136] In step 901 , when a pluggable optical module is inserted into an OLT device, the OLT device obtains a device certificate Cert_Dev from the pluggable optical module.
[0137] In step 902, the OLT device extracts the device vendor certificate from the device certificate Cert_Dev and uses the user certificate to verify the validity of the device vendor certificate; if the verification is valid, the device vendor public key in the device vendor certificate is used to verify the validity of the device certificate; if the device vendor certificate is invalid or the device certificate is invalid, the device is determined to be an illegal device, the process ends, and the OLT device does not load the pluggable optical module; if the device vendor certificate and the device certificate are both valid, the device public key Dev_Key_Public is extracted from the device certificate.
[0138] In step 903, the OLT device generates a random number Rand and sends the random number Rand to the pluggable optical module.
[0139] In step 904 , the pluggable optical module encrypts Rand using the device private key Dev_Key_Private, and sends the encryption result Rand_sign to the OLT device.
[0140] In step 905, the OLT device decrypts Rand_sign with Dev_Key_Public to obtain Rand_a; and compares Rand and Rand_a to see if they are equal. If they are equal, the pluggable optical module is determined to be a legitimate device and the pluggable optical module is accepted for loading. Otherwise, the pluggable optical module is determined to be an illegal device and the pluggable optical module is refused to be loaded.
[0141] Based on Example 2, also taking the pluggable optical module as an example, Figure 14 As shown, the authentication production method in the pluggable optical module also executes the above steps 801 to 805 , then proceeds to step 806 ′, and then executes step 807 .
[0142] In step 806', the device manufacturer V generates an unsigned device certificate for each pluggable optical module, which includes the device's unique security identifier (equivalent to the device identifier in Example 1) and the device's public key Dev_Key_Public; and uses the device manufacturer's private key to sign it to obtain a signed device certificate Cert_Dev.
[0143] At the same time, consumer C transmits the user certificate and equipment vendor certificate to the OLT device for authentication of the pluggable optical module. Figure 15 As shown, execute the above step 901, then execute step 902', and then execute steps 903-905.
[0144] In step 902', the OLT device uses the user certificate to verify the validity of the device vendor certificate based on the device vendor certificate stored in its own storage; if the verification is valid, the device vendor public key in the device vendor certificate is used to verify the validity of the device certificate; if the device vendor certificate is invalid or the device certificate is invalid, the device is determined to be an illegal device, the process ends, and the OLT device does not load the pluggable optical module; if the device vendor certificate and the device certificate are both valid, the device public key Dev_Key_Public is extracted from the device certificate, and subsequent authentication continues.
[0145] Through the above authentication process, the host can determine whether the inserted device product is legal. If it is a legal device, subsequent operations such as installation of the device product will be performed. If it is not legal, the device product will not be installed.
[0146] Embodiment 4:
[0147] Based on the device authentication generation method described in any one of Embodiments 1 to 3, this embodiment further provides a device product, which is produced by a device manufacturer, such as Figure 16 As shown, the device product storage area is programmed with a device certificate and a device private key in a device key pair. The device certificate and device key pair are generated based on the device authentication generation method described in any one of Examples 1 to 3. The device authentication generation method has been described in detail in Examples 1 to 3 and will not be repeated here.
[0148] The device product includes at least one of a pluggable optical module device, an on-chip storage space of a chip, and other pluggable devices suitable for a blade server; wherein, the pluggable optical module device includes at least one of an optical module with SFP package, QSFP package, QSFP-DD package, and OSFP package.
[0149] The device product is used in conjunction with a corresponding host, and the host authenticates the device product before installing the device product. When generating a device certificate and a device key pair according to the device authentication generation method described in Example 1, the device certificate includes a device vendor certificate, and the host includes a user certificate. When generating a device certificate and a device key pair according to the device authentication generation method described in Example 2, the device certificate does not include a device vendor certificate, and the host includes both a device vendor certificate and a user certificate.
[0150] Example 5:
[0151] like Figure 17 FIG. 1 is a schematic diagram of the architecture of a device authentication generation apparatus according to an embodiment of the present invention. The device authentication generation apparatus according to this embodiment includes one or more processors 21 and a memory 22. Figure 17 A processor 21 is taken as an example.
[0152] The processor 21 and the memory 22 may be connected via a bus or other means. Figure 17 The bus connection is taken as an example.
[0153] The memory 22 is a non-volatile computer-readable storage medium that can be used to store non-volatile software programs and non-volatile computer-executable programs, such as the device authentication generation method in Example 1. The processor 21 executes the device authentication generation method by running the non-volatile software programs and instructions stored in the memory 22.
[0154] The memory 22 may include high-speed random access memory and non-volatile memory, such as at least one disk storage device, flash memory device, or other non-volatile solid-state memory device. In some embodiments, the memory 22 may optionally include a memory remotely located relative to the processor 21, and such remote memory may be connected to the processor 21 via a network. Examples of such networks include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0155] The program instructions / modules are stored in the memory 22, and when executed by the one or more processors 21, the device authentication generation method in the above-mentioned embodiments 1 to 3 is executed, for example, the device authentication generation method described above is executed. Figure 1 、 Figure 5 、 Figure 7-Figure 9 as well as Figure 11-Figure 15 The steps shown.
[0156] It is worth noting that the information interaction, execution process, etc. between the modules and units within the above-mentioned devices and systems are based on the same concept as the processing method embodiment of the present invention. The specific content can be found in the description of the method embodiment of the present invention and will not be repeated here.
[0157] Those skilled in the art will understand that all or part of the steps in the various methods of the embodiments can be completed by instructing related hardware through a program, and the program can be stored in a computer-readable storage medium, which may include: read-only memory (ROM), random access memory (RAM), a disk or an optical disk, etc.
[0158] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A device authentication generation method, characterized in that: At least a device manufacturer, a consumer user, and a device product are involved, wherein the device product is produced by the device manufacturer. The authentication generation includes: The device manufacturer obtains a device vendor certificate issued by a consumer user; wherein the device vendor certificate is jointly generated by a first certificate subject and a first certificate signature, wherein the first certificate subject is composed of the device vendor identifier and the device vendor public key in the device vendor key pair, and the first certificate signature is obtained by signing the first certificate subject using the consumer user's user certificate; The device manufacturer also obtains the device identification of the device product, forms a second certificate subject with the device vendor certificate, the device identification of the device product, and the device public key in the device key pair, and uses the device vendor private key in the device vendor key pair to sign the second certificate subject to obtain a second certificate signature. The second certificate subject and the second certificate signature jointly generate a device certificate; Burn the device certificate and the device private key in the device key pair into the storage area of the device product; the user certificate is transmitted by the consumer user to the host so that the host that installs the device product can complete the authentication process of the device product; The host that installs the device product completes the authentication process of the device product, specifically including: the host obtains the device vendor certificate from the device certificate, obtains the first certificate signature from the device vendor certificate, and uses the user certificate to verify the validity of the first certificate signature; after verifying the validity of the first certificate signature, obtains the device vendor public key in the device vendor key pair from the device vendor certificate, obtains the second certificate signature from the device certificate, and uses the device vendor public key to verify the validity of the second certificate signature; after verifying the validity of the second certificate signature, obtains the device public key in the device key from the device certificate, verifies whether the device public key matches the device private key in the storage area of the device product, and if it is verified that the device public key matches the device private key, the authentication process of the device product is completed.
2. The device authentication generation method according to claim 1, characterized in that: Verifying whether the device public key matches the device private key in the storage area of the device product specifically includes: The host sends the generated random number to the device product, and obtains an encryption result obtained by the device product encrypting the random number according to the device private key; The host decrypts the encryption result using the device public key to obtain a decryption result, and determines whether the decryption result is consistent with the random number; If the decryption result is consistent with the random number, it is verified that the device public key matches the device private key.
3. The device authentication generation method according to claim 1, characterized in that: The using the user certificate to verify the validity of the first certificate signature specifically includes: The host obtains the first certificate subject in the device vendor certificate, and uses the user certificate to issue the first certificate subject to obtain an issuance result; Determine whether the issuance result is consistent with the first certificate signature; if the issuance result is consistent with the first certificate signature, verify that the validity of the first certificate signature is passed.
4. The device authentication generation method according to any one of claims 1 to 3, characterized in that: The device product includes at least one of a pluggable optical module device, an on-chip storage space of a chip, and other pluggable devices suitable for a blade server; wherein, the pluggable optical module device includes at least one of an optical module with SFP package, QSFP package, QSFP-DD package, and OSFP package.
5. A device authentication generation method, characterized in that: At least a device manufacturer, a consumer user, and a device product are involved, wherein the device product is produced by the device manufacturer. The authentication generation includes: The device manufacturer obtains a device vendor certificate issued by a consumer user; wherein the device vendor certificate is jointly generated by a first certificate subject and a first certificate signature, wherein the first certificate subject is composed of the device vendor identifier and the device vendor public key in the device vendor key pair, and the first certificate signature is obtained by signing the first certificate subject using the consumer user's user certificate; The device manufacturer also obtains the device identification of the device product, uses the device identification of the device product and the device public key in the device key pair to form a second certificate subject, and uses the device manufacturer's private key in the device manufacturer's key pair to sign the second certificate subject to obtain a second certificate signature. The second certificate subject and the second certificate signature jointly generate a device certificate; Burn the device certificate and the device private key in the device key pair into the storage area of the device product; the user certificate and the device vendor certificate are transmitted by the consumer user to the host so that the host that installs the device product can complete the authentication process of the device product; The host that installs the device product completes the authentication process of the device product, specifically including: the host obtains a first certificate signature from the device vendor certificate, and uses a user certificate to verify the validity of the first certificate signature; after verifying the validity of the first certificate signature, obtains the device vendor public key in the device vendor key pair from the device vendor certificate, and obtains a second certificate signature from the device certificate, and uses the device vendor public key to verify the validity of the second certificate signature; after verifying the validity of the second certificate signature, obtains the device public key in the device key from the device certificate, verifies whether the device public key matches the device private key in the storage area of the device product, and if it is verified that the device public key matches the device private key, the authentication process of the device product is completed.
6. The device authentication generation method according to claim 5, characterized in that: Verifying whether the device public key matches the device private key in the storage area of the device product specifically includes: The host sends the generated random number to the device product, and obtains an encryption result obtained by the device product encrypting the random number according to the device private key; The host decrypts the encryption result using the device public key to obtain a decryption result, and determines whether the decryption result is consistent with the random number; If the decryption result is consistent with the random number, it is verified that the device public key matches the device private key.
7. The device authentication generation method according to claim 5, characterized in that: The using the user certificate to verify the validity of the first certificate signature specifically includes: The host obtains the first certificate subject in the device vendor certificate, and uses the user certificate to issue the first certificate subject to obtain an issuance result; Determine whether the issuance result is consistent with the first certificate signature; if the issuance result is consistent with the first certificate signature, verify that the validity of the first certificate signature is passed.
8. A device based on a device authentication generation method, characterized in that: The device is manufactured by a device manufacturer, and a device certificate and a device private key in a device key pair are burned into a storage area of the device. The device certificate and device key pair are generated based on the device authentication generation method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Certificate issuing method, device and system for intelligent equipment
CN110138562A
Article authentication system, authentication server and article authentication method
JP2015162694A