Security authentication method and system of communication device, storage medium and communication device
By implementing multi-level key authentication and power-down operations in communication equipment, the problem of insufficient security of management boards and service boards is solved, thereby improving the security of the equipment and the overall communication security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-31
- Publication Date
- 2026-03-31
AI Technical Summary
The management board and service board in existing communication equipment have poor security and are easily hacked, making it difficult to guarantee equipment security.
By implementing multi-level key authentication between the main management board and the service board, including first key authentication, second key authentication and third key authentication, security verification is performed using encryption devices and controllers, the number of authentication failures is recorded and a power-down operation is performed when a threshold is reached, and a master-slave election algorithm is used to determine the main management board.
It improves the security of communication equipment, reduces the risk of key leakage, enhances the coupling authentication management between the main management board and the service board, and prevents the equipment from being cracked and copied.
Smart Images

Figure CN115694992B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication security, and in particular to security authentication methods, systems, storage media, and communication devices for communication equipment. Background Technology
[0002] Currently, communication equipment typically includes management boards and service boards. The management board can be a switching network board, containing functions such as a management engine, while the service board is used to implement specific communication services. However, management boards and service boards generally only have identification registers or manufacturer IDs set up for easy identification, but these are easily cracked by malicious actors, resulting in poor security and making it difficult to guarantee the security of the communication equipment.
[0003] Therefore, how to improve the security of communication equipment is a technical problem that urgently needs to be solved by those skilled in the art. Summary of the Invention
[0004] The purpose of this application is to provide a security authentication method, system, storage medium, and communication device for communication devices, which can provide device security for communication devices.
[0005] To address the aforementioned technical problems, this application provides a security authentication method for communication devices, the specific technical solution of which is as follows:
[0006] Upon receiving the security authentication command, the main management board performs the first key authentication using its own first encryption device and first controller.
[0007] If the first key authentication passes and the second key authentication pass flag uploaded by the target service board to the main management board is received, the main management board and the target service board perform a third key authentication.
[0008] If the third key authentication is successful, the main management board instructs the target service board to grant multiple service permissions.
[0009] Optionally, the third-key authentication between the main management board and the target service board includes:
[0010] The main management board issues authentication commands to the target service board;
[0011] After receiving the plaintext corresponding to the authentication instruction sent by the target service board, the plaintext is encrypted using the first key algorithm by the first encryption device to obtain the ciphertext;
[0012] The ciphertext is sent to the target service board. If the decryption obtained by the second controller on the target service board is consistent with the plaintext, the main management board confirms that the target service board has passed authentication.
[0013] Optionally, if the second key authentication pass flag uploaded by the target service board to the main management board is not received, the method further includes:
[0014] Record the number of times the algorithm decryption authentication failed for the target service board;
[0015] If the number of failed decryption authentication attempts by the algorithm meets the first failure threshold, the target service board is authenticated as an illegal service board, and a power-off operation is performed on the illegal service board.
[0016] Optionally, if the third key authentication fails, the method further includes:
[0017] Record the number of authentication failures for the business board corresponding to the target business board;
[0018] If the number of authentication failures of the service board meets the second failure threshold, the target service board is authenticated as an illegal service board, and a power-off operation is performed on the illegal service board.
[0019] Optionally, if the communication device has at least two management boards before receiving the security authentication command, the method further includes:
[0020] The management board in the highest slot obtains the presence information of other management boards;
[0021] If the other management boards are in place, the master management board is elected from among the in-place management boards using a master-slave election algorithm;
[0022] If none of the other management boards are in place, the management board in the highest slot will be used as the main management board.
[0023] Optionally, if the main management board malfunctions or the first key authentication fails, the method further includes:
[0024] A new master management board is elected from among the remaining management boards using the master-slave election algorithm.
[0025] This application also provides a security authentication method for a communication device, applied to a target service board, including:
[0026] After the target service board successfully performs the second key authentication, it sends the second key authentication success flag to the main management board.
[0027] After the main management board performs third key authentication based on the second key authentication pass flag, it obtains the instruction information issued by the main management board and opens multiple service permissions according to the instruction information.
[0028] Optionally, the process of the target service board performing second key authentication includes:
[0029] After the target service board goes online, the second controller on the target service board sends a second plaintext message to the second encryption device on the target service board.
[0030] After the second encryption device encrypts the second plaintext using the second key algorithm and generates the second ciphertext, the second ciphertext returned by the second encryption device is received.
[0031] The second controller is used to perform algorithmic decryption and authentication on the second ciphertext.
[0032] If the algorithm successfully decrypts and authenticates, it confirms that the target service board has successfully performed the second key authentication.
[0033] This application also provides a communication device, including:
[0034] At least one management board, each of the management boards comprising:
[0035] A first cryptographic device and a first controller for performing first key authentication;
[0036] When the management board is the main management board, the first controller is used to perform a first key authentication using its own first encryption device and first controller; if the first key authentication is successful and a second key authentication success flag is received from the target service board and uploaded to the main management board, the main management board and the target service board perform a third key authentication; if the third key authentication is successful, the main management board instructs the target service board to open multiple service permissions;
[0037] At least one service board, each of the service boards comprising:
[0038] A second encryption device and a second controller perform second key authentication. The second controller is used to upload the second key authentication success flag to the main management board after the second key authentication is successfully performed on the service board.
[0039] This application also provides a security authentication system for communication devices, including:
[0040] The main management board authentication module is used to perform first key authentication using its own first encryption device and first controller after receiving a security authentication command;
[0041] The business authentication module is used to perform third key authentication with the target business board if the first key authentication is successful and a second key authentication success flag uploaded by the target business board to the main management board is received.
[0042] The permission configuration module is used to instruct the target service board to grant multiple service permissions if the third key authentication is successful.
[0043] This application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method described above.
[0044] This application provides a security authentication method for a communication device, comprising: upon receiving a security authentication command, the main management board performs a first key authentication using a first encryption device and a first controller contained therein; if the first key authentication passes and a second key authentication pass flag is received from a target service board and uploaded to the main management board, the main management board performs a third key authentication with the target service board; if the third key authentication passes, the main management board instructs the target service board to grant multiple service permissions.
[0045] This application implements a system that, upon receiving a security authentication command, first performs a first key authentication on itself. After the first key authentication is successful, if a second key authentication success flag is received, then security authentication between the main management board and the service board is performed. This improves the security of the main management board and the service board in the communication equipment, strengthens the coupled authentication management between the main management board and the service board, making the communication equipment less susceptible to cracking and copying. Furthermore, the first key authentication performed by the main management board and the second key authentication performed by the service board can be executed independently, reducing the risk of key leakage and improving the communication security of the main management board, as well as the overall communication security of the communication equipment.
[0046] This application also provides a security authentication system for communication devices, a computer-readable storage medium, and a communication device, which have the aforementioned beneficial effects, and will not be elaborated here. Attached Figure Description
[0047] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0048] Figure 1 A flowchart illustrating a security authentication method for a management board in a communication device, provided as an embodiment of this application;
[0049] Figure 2 A flowchart illustrating a security authentication method for a service board in a communication device, provided as an embodiment of this application;
[0050] Figure 3 A security authentication flowchart for a service board provided in this application embodiment;
[0051] Figure 4This is a security authentication flowchart of another security authentication method for a communication device provided in an embodiment of this application;
[0052] Figure 5 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application;
[0053] Figure 6 This is a schematic diagram of a security authentication system for a communication device provided in an embodiment of this application. Detailed Implementation
[0054] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0055] See Figure 1 , Figure 1 This is a flowchart illustrating a security authentication method for a communication device provided in an embodiment of this application. This security authentication method can be applied to any communication device including a management board and a service board. The security authentication method includes:
[0056] S101: After receiving the security authentication command, the main management board uses its own first encryption device and first controller to perform the first key authentication;
[0057] Upon receiving the security authentication command, the main management board first performs a security verification on itself. The specific content and format of the security authentication command are not limited here; it is used to instruct the initiation of security authentication for the communication device. Any command that can achieve this function can be used as the security authentication command in this step.
[0058] It should also be noted that this embodiment assumes the main management board in the management board has already been identified before performing this step. When performing this step, the main management board's own security authentication can be performed directly.
[0059] Specifically, the main management board uses its own first encryption device and first controller to perform first key verification. This process is essentially a mutual authentication between the first controller and the first encryption device, preventing the first encryption device from being maliciously tampered with. In the embodiments of this application and the following embodiments, the main management board includes a first controller and a first encryption device, and the service board includes a second controller and a second encryption device. Both the first controller and the second controller can be processors or main control chips on their respective boards, while the first encryption device and the second encryption device can be encryption chips containing encryption algorithms.
[0060] One feasible implementation method is as follows:
[0061] S1011: The main management board uses its own first controller to send the first plaintext to the first encryption device;
[0062] S1012: After the first encryption device encrypts the first plaintext using the first key algorithm and generates the first ciphertext, it receives the first ciphertext returned by the second encryption device;
[0063] S1013: The first controller performs algorithm decryption and authentication on the first ciphertext;
[0064] S1014: If the algorithm successfully decrypts and authenticates, grant the main management board the authentication permission for the business board.
[0065] After power-on, the main management board sends the first plaintext to the first encryption device via the first controller. This sending can be done directly or through internal communication middleware on the main management board, such as a multiplexer or programmable device. To ensure authentication security, the first plaintext can be randomly generated by the first controller. The first encryption device then encrypts the first plaintext using its own first key algorithm to obtain the first ciphertext and returns it to the first controller. The first controller performs algorithm decryption authentication on the first ciphertext. Once successful, the main management board's service board authentication permissions are granted. It can be seen that the first controller plays two roles in this process: generating the first plaintext and performing algorithm decryption authentication on the first ciphertext returned by the first encryption device. It is easy to understand that the decryption algorithm used by the first controller in performing the algorithm decryption authentication process should correspond to the first key algorithm used by the first encryption device. If either the first controller or the first encryption device is maliciously attacked, the algorithm decryption authentication will directly fail.
[0066] If the algorithm decryption and authentication are successful, the main management board can then be granted business board authentication permissions. Business board authentication permissions mean that the main management board itself has passed authentication and can perform business board authentication. Other management boards that have not been granted business board authentication permissions cannot perform the subsequent business board authentication process.
[0067] S102: If the first key authentication passes and the second key authentication pass flag uploaded by the target service board to the main management board is received, the main management board and the target service board perform a third key authentication.
[0068] After the first key authentication on the main management board is successful, if a second key authentication success flag is received from the target service board and uploaded to the main management board, a third key authentication can be performed between the main management board and the target service board. Specifically, the main management board can switch to the link where the target service board is located to perform the third key authentication with the target service board. This process can also be implemented by communication middleware, such as a multiplexer or a programmable device, contained in the main management board. The target service board can be any service board that uploaded the second key authentication success flag.
[0069] This step assumes that the target service board has already successfully completed the second key authentication. It's important to note that the main management board can receive second key authentication success flags uploaded by multiple target service boards simultaneously or sequentially, and can choose to authenticate with multiple target service boards simultaneously or sequentially.
[0070] The main management board can send authentication commands to the target service board via the link to initiate the security authentication process for the target service board. Prior to this, the main management board can also perform an on-premises check on the target service board. Once the target service board is confirmed to be online, the main management board can then send authentication commands to it.
[0071] One possible way to perform this step is as follows:
[0072] S1021: The main management board issues an authentication command to the target service board;
[0073] S1022: After receiving the plaintext corresponding to the authentication instruction sent by the target service board, the plaintext is encrypted using the first key algorithm through the first encryption device to obtain the ciphertext;
[0074] S1023: The ciphertext is sent to the target service board. If the decryption text obtained by the second controller on the target service board is consistent with the plaintext, the main management board confirms that the target service board has passed authentication.
[0075] The main management board first sends an authentication command to the target service board. Upon receiving the command, the target service board returns the plaintext corresponding to the command to the main management board. The main management board then uses its first encryption device to encrypt the plaintext using its first key algorithm, obtaining ciphertext. Afterward, the main management board sends the ciphertext to the target service board. The target service board uses its second controller to decrypt the ciphertext, obtaining the decrypted text, which is then compared with the plaintext it sent to the main management board. If they match, the target service board is considered to have passed authentication.
[0076] After receiving the authentication command, the target service board needs to generate the corresponding plaintext. During this process, the authentication command can be parsed to directly obtain the plaintext, or plaintext can be generated based on the feature information contained in the authentication command. This feature information may include the identity information of the main management board, the command sending time, etc., allowing the first encryption device on the main management board to confirm that the authentication command was accurately sent to the target service board via the plaintext. Alternatively, the generated plaintext may be unrelated to the authentication command and used only for secure authentication between the main management board and the target service board.
[0077] Upon receiving the plaintext, the first encryption device on the main management board encrypts it using its built-in first key algorithm to obtain the first ciphertext. The first key algorithm is not limited here; it can be any encryption algorithm set by those skilled in the art, such as a symmetric encryption algorithm or an asymmetric encryption algorithm.
[0078] S103: If the third key authentication is successful, the main management board instructs the target service board to open multiple service permissions;
[0079] If the main management board successfully authenticates the target service board's third key, it can then instruct the target service board to grant multiple service permissions. These permissions are used to receive external communication task data, enabling the service board to perform communication data calculations. The specific content of the granted service permissions is not limited here, but may include, but is not limited to, the permission for the target service board to interact with external communication data.
[0080] This application embodiment implements a method whereby, upon receiving a security authentication command, the device first performs a first key authentication. After the first key authentication passes, if a second key authentication pass flag is received, then security authentication between the main management board and the service board is performed. This improves the security of the main management board and the service board in the communication device, strengthens the coupled authentication management between the main management board and the service board, making the communication device less susceptible to cracking and copying. Furthermore, the first key authentication performed by the main management board and the second key authentication performed by the service board can be executed independently, reducing the risk of key leakage and improving the communication security of the main management board, as well as the overall communication security of the communication device.
[0081] Based on the previous embodiment, as a preferred embodiment, if the second key authentication pass flag uploaded by the target service board to the main management board is not received, it indicates that the target service board has failed its own authentication. In this case, the number of algorithm decryption authentication failures corresponding to the target service board can be recorded. If the number of algorithm decryption authentication failures meets the first failure threshold, the target service board is authenticated as an illegal service board, and a power-off operation is performed on the illegal service board.
[0082] Similarly, based on the previous embodiment, if the main management board fails to authenticate the target service board with the third key, it can record the number of authentication failures of the service board corresponding to the target service board. If the number of authentication failures of the service board meets the second failure threshold, the target service board can also be authenticated as an illegal service board, and the illegal service board can also be powered down.
[0083] The first and second failure thresholds are not numerically limited and can be set by those skilled in the art.
[0084] Based on the above embodiments, as a preferred embodiment, the following describes how to determine the main management board:
[0085] Communication equipment often employs multiple management boards to achieve redundancy. When at least two management boards are present, the management board in the highest slot can obtain the availability information of the other management boards. If other management boards are present, a master-slave election algorithm is used to elect a master management board from among them. If none of the other management boards are present, the management board in the highest slot becomes the master management board. The process begins by selecting a management board according to a specific slot order to obtain the availability information of the remaining management boards. If multiple management boards are online simultaneously, a master-slave election algorithm is used to elect a master management board. The specific master-slave election algorithm used is not limited here; for example, the Bully algorithm can be used.
[0086] In addition, when the main management board malfunctions or fails to perform the first key authentication, a new main management board can be elected from among the remaining management boards using a master-slave election algorithm.
[0087] See Figure 2 , Figure 2 This application provides a flowchart of a security authentication method for a service board in a communication device, as shown in the embodiments of this application. This application also provides a security verification method for a communication device, applied to a target service board, which includes:
[0088] S201: After the second key authentication is successfully performed on the target service board, the second key authentication success flag is sent to the main management board;
[0089] S202: After the main management board performs the third key authentication based on the second key authentication pass flag, it obtains the instruction information issued by the main management board and opens multiple service permissions according to the instruction information.
[0090] It should be noted that the target service board in this application embodiment is used to indicate any service board that can perform security verification with the main management board, and is not specifically designated.
[0091] Once the target service board has successfully performed its own second key authentication, it can send a second key authentication success flag to the main management board. There are no restrictions on the specific content or format of the second key authentication success flag; any information that informs the main management board that the target management board has completed second key authentication can be used as the second key authentication success flag.
[0092] Based on the above embodiments, as a preferred embodiment, no limitation is made here on how the target service board performs the second key authentication; see [link to relevant documentation]. Figure 3 , Figure 3 A security authentication flowchart for a service board provided in this application embodiment can be implemented in the following way:
[0093] S301: After the target service board is online, the second controller on the target service board sends the second plaintext to the second encryption device on the target service board;
[0094] S302: After the second encryption device performs the second key algorithm to encrypt the second plaintext and generates the second ciphertext, the second ciphertext returned by the second encryption device is received;
[0095] S303: The second controller performs algorithm decryption authentication on the second ciphertext;
[0096] S304: If the algorithm decryption and authentication are successful, the second controller sends the second key authentication pass flag to the main management board.
[0097] Similarly, the second plaintext can also be plaintext randomly generated by the second controller.
[0098] After the service board powers on normally, its second controller communicates with the second encryption device on the same board and sends a second plaintext message. Upon receiving the plaintext, the second encryption device executes the second key encryption algorithm to encrypt it, generating a second ciphertext message which is then fed back to the service board's second controller for decryption. The decrypted message is compared with the sent plaintext message to determine if verification is successful. If the service board successfully authenticates the second key, its second controller sends a second key authentication success flag to the main management board. The service board then enters a pending first key authentication mode and can access some debugging functions. These partial debugging functions mean that while the service board has successfully authenticated, the main management board's own verification has not been executed or completed. In this mode, the main management board can only perform partial debugging, such as viewing the service board's configuration information, name, and attributes, but cannot control the service board to perform any actual communication services.
[0099] If the authentication of the second key by the service board fails, the second controller of the service board can repeat the above authentication process until the algorithm decryption authentication fails and the failure count threshold is met. The target service board will be authenticated as an illegal service board, and a power-off operation will be performed on the illegal service board. Log information can also be reported to the main management board.
[0100] See Figure 4 , Figure 4 This application provides a security authentication flowchart for another security authentication method for communication devices, which specifically includes:
[0101] The first step is for the main management board, after successful authentication with the first key, to obtain the presence information of the service board.
[0102] The second step is to determine if the business board is in place; if not, the process ends; if yes, proceed to the third step.
[0103] The third step is to wait for the second key authentication completion flag from the service board.
[0104] Step 4: Determine whether the second key authentication pass flag of the target service board has been received; if yes, proceed to step 5; otherwise, end the process.
[0105] Step 5: Use the first controller to switch to the link where the target service board is located;
[0106] Step 6: Issue authentication instructions to the target business board;
[0107] Step 7: The target business board generates the plaintext corresponding to the authentication command and returns it to the main management board;
[0108] Step 8: The first encryption device performs the first key algorithm to encrypt the plaintext, obtaining ciphertext, and feeds it back to the service board;
[0109] Step 9: The second controller on the target business board decrypts the ciphertext to obtain the decoded text;
[0110] Step 10: The business board determines whether the parsed text and plaintext are consistent; if yes, proceed to step 11; if no, proceed to step 12.
[0111] Step 11: The main management board confirms that the target business board has passed authentication and grants all business permissions to the target business board, thus ending the process;
[0112] Step 12: Determine if the business board authentication failure meets the failure count threshold; if yes, proceed to step 13; otherwise, return to step 7.
[0113] Step 13: Authentication the target service board as an illegal service board, and power-down operation on the illegal service board;
[0114] In the above process, if the service is not in place or the second key authentication pass flag of the target service board is not received when performing the second and fourth steps, the current state can be maintained instead of directly ending the process. That is, the waiting state is maintained until the service board is in place or the second key authentication pass flag of the target service board is received before proceeding to the subsequent steps.
[0115] As can be seen from this embodiment, after the service board completes the second key authentication within its board, it needs to complete the first key authentication with the main management board to establish the communication equipment system functions. The main management board and the service board achieve strong coupling in authentication management, making the overall communication equipment system difficult to crack or copy. The first key belonging to the main management board and the second key belonging to the service board can be managed separately, mutually checking and balancing each other, ensuring the security of keys and encryption chips, and reducing the risk of key leakage.
[0116] See Figure 5 , Figure 5 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application. The communication device includes:
[0117] At least one management board, each of the management boards comprising:
[0118] A first cryptographic device and a first controller for performing first key authentication;
[0119] When the management board is the main management board, the first controller is used to perform a first key authentication using its own first encryption device and first controller; if the first key authentication is successful and a second key authentication success flag is received from the target service board and uploaded to the main management board, the main management board and the target service board perform a third key authentication; if the third key authentication is successful, the main management board instructs the target service board to open multiple service permissions;
[0120] At least one service board, each of the service boards comprising:
[0121] A second encryption device and a second controller perform second key authentication. The second controller is used to upload the second key authentication success flag to the main management board after the second key authentication is successfully performed on the service board.
[0122] In addition, the communication device may also include a communication backplane that is connected to the management board and the service board via a communication bus.
[0123] The process of the business board performing the second key authentication can be found above and will not be repeated here.
[0124] See Figure 6 , Figure 6This application provides a schematic diagram of a security authentication system for communication devices. This system can be compared and contrasted with the security authentication methods for communication devices disclosed above. Specifically, it may include:
[0125] The main management board authentication module is used to perform first key authentication using its own first encryption device and first controller after receiving a security authentication command;
[0126] The business authentication module is used to perform third key authentication with the target business board if the first key authentication is successful and a second key authentication success flag uploaded by the target business board to the main management board is received.
[0127] The permission configuration module is used to instruct the target service board to grant multiple service permissions if the third key authentication is successful.
[0128] Based on the above embodiments, as a preferred embodiment, the business authentication module includes:
[0129] The instruction issuing unit is used to issue authentication instructions to the target service board;
[0130] The encryption unit is used to encrypt the plaintext corresponding to the authentication instruction sent by the target service board by performing a first key algorithm on the plaintext through the first encryption device to obtain ciphertext;
[0131] The third key authentication unit is used to send the ciphertext to the target service board. If the decryption text obtained by the second controller on the target service board is consistent with the plaintext, the main management board confirms that the target service board has passed authentication.
[0132] Based on the above embodiments, as a preferred embodiment, the security authentication system may further include:
[0133] The first power-down module is used to record the number of algorithm decryption and authentication failures corresponding to the target service board; if the number of algorithm decryption and authentication failures meets the first failure threshold, the target service board is authenticated as an illegal service board, and a power-down operation is performed on the illegal service board.
[0134] Based on the above embodiments, as a preferred embodiment, the security authentication system may further include:
[0135] The second power-down module is used to record the number of authentication failures of the service board corresponding to the target service board; if the number of authentication failures of the service board meets the second failure number threshold, the target service board is authenticated as an illegal service board, and a power-down operation is performed on the illegal service board.
[0136] Based on the above embodiments, as a preferred embodiment, if the communication device has at least two management boards, it further includes:
[0137] The main management board confirmation module is used to obtain the presence information of other management boards using the management board in the highest slot; if the other management boards are in place, the main management board is elected from the in-place management boards using a master-slave election algorithm; if the remaining management boards are not in place, the management board in the highest slot is taken as the main management board.
[0138] Based on the above embodiments, as a preferred embodiment, it further includes:
[0139] The main management board update module is used to elect a new main management board from among the remaining management boards using the master-slave election algorithm if the main management board malfunctions or the first key authentication fails.
[0140] This application also provides a computer-readable storage medium storing a computer program thereon, which, when executed, can implement the steps of the methods provided in the above embodiments. The storage medium may include various media capable of storing program code, such as a USB flash drive, a portable hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0141] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. As the system provided in the embodiments corresponds to the method provided in the embodiments, the description is relatively simple; relevant parts can be found in the method section.
[0142] This document uses specific examples to illustrate the principles and implementation methods of this application. The descriptions of the embodiments above are only for the purpose of helping to understand the method and core ideas of this application. It should be noted that those skilled in the art can make several improvements and modifications to this application without departing from the principles of this application, and these improvements and modifications also fall within the protection scope of the claims of this application.
[0143] It should also be noted that, in this specification, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
Claims
1. A security authentication method of a communication device, applied to a main management board, characterized in that, The method comprises the following steps: After receiving the security authentication instruction, the main management board performs first key authentication by using the first encryptor and the first controller contained in the main management board; If the first key authentication is passed and a second key authentication pass flag uploaded by the target service board to the main management board is received, the main management board performs third key authentication with the target service board; the second key authentication pass flag is used to indicate that the target service board performs second key authentication by using the second encryptor and the second controller contained in the target service board; If the third key authentication is passed, the main management board instructs the target service board to open a plurality of service permissions; The third key authentication performed by the main management board and the target service board comprises the following steps: The main management board issues an authentication instruction to the target service board; After receiving the plaintext corresponding to the authentication instruction sent by the target service board, the plaintext is encrypted by the first encryptor to obtain ciphertext; If the plaintext obtained by decrypting the ciphertext by the second controller on the target service board is consistent with the plaintext, the main management board confirms that the target service board passes the authentication.
2. The security authentication method of claim 1, wherein, If the second key authentication pass flag uploaded by the target service board to the main management board is not received, the method further comprises the following steps: Record the number of algorithm decryption authentication failures corresponding to the target service board; If the number of algorithm decryption authentication failures satisfies a first failure number threshold, the target service board is authenticated as an illegal service board, and a power-off operation is performed on the illegal service board.
3. The security authentication method of claim 1, wherein, If the third key authentication is not passed, the method further comprises the following steps: Record the number of service board authentication failures corresponding to the target service board; If the number of service board authentication failures satisfies a second failure number threshold, the target service board is authenticated as an illegal service board, and a power-off operation is performed on the illegal service board.
4. The security authentication method according to any one of claims 1 to 3, characterized by, Before receiving the security authentication instruction, if there are at least two management boards in the communication device, the method further comprises the following steps: The management board with the highest slot obtains the in-place information of other management boards; If the other management boards are in place, the main management board is elected from the management boards in place by using a master-slave election algorithm; If the remaining management boards are not in place, the management board with the highest slot is taken as the main management board.
5. The security authentication method of claim 4, wherein, If the main management board is abnormal or the first key authentication is not passed, the method further comprises the following steps: A new main management board is elected from the remaining management boards by using the master-slave election algorithm.
6. A security authentication method of a communication device applied to a target service board, characterized by, The method comprises the following steps: After the target service board performs second key authentication, the second key authentication pass flag is sent to the main management board; After the main management board performs third key authentication based on the second key authentication pass flag, the indication information issued by the main management board is obtained, and a plurality of service permissions are opened according to the indication information; The main management board is used to perform the security authentication method of the communication device according to any one of claims 1-5.
7. The security authentication method of claim 6, wherein, The process of performing second key authentication by the target service board comprises the following steps: After the target service board is online, a second controller on the target service board sends a second plaintext to a second encryption device on the target service board; After the second encryption device performs second key algorithm encryption on the second plaintext and generates a second ciphertext, the second ciphertext returned by the second encryption device is received; The second ciphertext is algorithmically decrypted by the second controller; If the algorithmic decryption is successful, it is confirmed that the target service board passes the second key authentication.
8. A communication device, characterized by The system comprises: At least one management board, each of which comprises: a first encryption device and a first controller for performing first key authentication; When the management board is a master management board, the first controller is configured to perform first key authentication by using the first encryption device and the first controller contained therein; If the first key authentication is passed and a second key authentication pass flag uploaded by a target service board to the master management board is received, the master management board performs third key authentication with the target service board; if the third key authentication is passed, the master management board instructs the target service board to open a plurality of service permissions; At least one service board, each of which comprises: a second encryption device and a second controller for performing second key authentication, and the second controller is configured to upload the second key authentication pass flag to the master management board after the service board passes the second key authentication.
9. A security authentication system of a communication device, characterized by comprising: The system comprises: a master management board authentication module configured to perform first key authentication by using the first encryption device and the first controller contained therein after receiving a security authentication instruction; a service authentication module configured to perform third key authentication with a target service board if the first key authentication is passed and a second key authentication pass flag uploaded by the target service board to the master management board is received; the second key authentication pass flag is used to indicate that the target service board passes the second key authentication by using the second encryption device and the second controller contained therein; a permission configuration module configured to instruct the target service board to open a plurality of service permissions if the third key authentication is passed; The service authentication module comprises: an instruction sending unit configured to send an authentication instruction to the target service board; an encryption unit configured to perform first key algorithm encryption on the plaintext corresponding to the authentication instruction sent by the target service board by using the first encryption device to obtain a ciphertext after the plaintext is received; a third key authentication unit configured to send the ciphertext to the target service board, and if the plaintext obtained by decrypting the ciphertext by a second controller on the target service board is consistent with the plaintext, the master management board confirms that the target service board passes the authentication.
10. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by a processor to implement the steps of the security authentication method of the communication device according to any one of claims 1-5 or any one of claims 6-7.
Citation Information
Patent Citations
Management boards, modularized equipment with double management boards, and electing method of master control board
CN102820973A
Credible starting method suitable for service board in VPX device
CN105930732A
Authentication method, equipment and system
CN110299996A