Pairing hardware components to authorize operation
By establishing a trust relationship between the hardware components of the electronic device and comparing the settings associated with the authorization function, the problem of safely maintaining the functional configuration across multiple hardware components is solved, and the secure authorization and functional stability of the hardware components are achieved.
Patent Information
- Application Number
- CN202080104869.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-07-20
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2040-07-20
AI Technical Summary
The prior art is difficult to safely maintain a predetermined functional configuration of the device across multiple hardware components in an electronic device, preventing unauthorized replacement and modification of the hardware components.
By establishing a trust relationship between hardware components, the processor initiates the pairing process, sharing and verifying identification information, comparing settings associated with authorization functions, and authorizing operations of hardware components based on matching settings.
It realizes safe maintenance of functional configurations across multiple hardware components during product life, preventing unauthorized hardware replacement and transformation, and improving the security and functional stability of the equipment.
Smart Images

Figure CN116134426B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure generally relates to pairing hardware components to authorize operations. Background Art
[0002] Electronic devices (including computing devices) may be composed of a variety of different hardware components. These hardware components may be replaced in the electronic device. Summary of the invention
[0003] According to a first aspect of the present disclosure, a device for pairing hardware components is provided, comprising: a first hardware component, comprising: a first memory; and a first processor, used to: initiate pairing between the first hardware component and a second hardware component to establish a trust relationship between the first hardware component and the second hardware component; in response to successful pairing between the first hardware component and the second hardware component, compare a first setting of the first hardware component associated with a first authorized function with a second setting of the second hardware component associated with a second authorized function, the first authorized function being the same as the second authorized function; and in response to determining that the second setting corresponds to the first setting, authorize the operation of the second hardware component.
[0004] According to a second aspect of the present disclosure, a method for pairing hardware components is provided, comprising: initiating pairing of a first hardware component and a second hardware component by a processor, the pairing establishing a trust relationship between the first hardware component and the second hardware component; in response to successful pairing between the first hardware component and the second hardware component, determining by the processor that a first setting associated with a first authorized function enabled in the first hardware component and a second setting associated with a second authorized function enabled in the second hardware component match, and the first authorized function is the same as the second authorized function; and authorizing operation of the second hardware component by the first hardware component based on determining that the first setting matches the second setting, and authorizing operation of the first hardware component by the second hardware component.
[0005] According to a second aspect of the present disclosure, a non-transitory computer-readable medium is provided, on which computer-readable instructions are stored. When the computer-readable instructions are executed, a processor of a computing device is caused to: share identification information between a first hardware component and a second hardware component; verify the identification information to establish a trust relationship between the first hardware component and the second hardware component; in response to determining that the trust relationship has been established between the first hardware component and the second hardware component, verify a first setting of the first hardware component associated with a first authorized function and a second setting of the second hardware component associated with a second authorized function, the first authorized function being the same as the second authorized function; and in response to successful verification of the first setting and the second setting, authorize the operation of the first hardware component and / or the second hardware component. BRIEF DESCRIPTION OF THE DRAWINGS
[0006] Features of the present disclosure are illustrated by way of example and not limitation in the following figures, in which like numerals represent like elements, and in which:
[0007] Figure 1 depicts a block diagram of an example device that may include a first hardware component that may initiate pairing with a second hardware component to establish a trust relationship and authorize operation of the second hardware component;
[0008] Figure 2 shows that it can be included in Figure 1 A block diagram of an example system of the example devices depicted;
[0009] Figure 3 A flow chart illustrating an example method for initiating pairing between a first hardware component and a second hardware component to establish a trust relationship and for authorizing operation of the first hardware component and / or the second hardware component;
[0010] Figure 4 A block diagram of an exemplary non-transitory computer-readable medium having stored thereon may store computer-readable instructions that authorize operation of a first hardware component and / or a second hardware component is depicted. DETAILED DESCRIPTION
[0011] For the purpose of simplicity and illustration, the present disclosure is described primarily by reference to examples. In the following description, various specific details are proposed to provide a thorough understanding of the present disclosure. However, it is apparent that the present disclosure can be practiced without being limited to these specific details. In other examples, some methods and structures are not described in detail to avoid unnecessary confusion of the present disclosure.
[0012] Throughout this disclosure, the terms "a" and "an" are intended to mean at least one of a particular element. As used herein, the term "comprising" means including but not limited to. The term "based on" means at least partially based on.
[0013] Disclosed herein are devices, systems, methods, and computer-readable media that can establish trust relationships between hardware components and authorize the operation of the hardware components based on the established trust relationships. Electronic devices such as printers, personal computers, etc. can be composed of a variety of different hardware components. The hardware components can include various types of control boards (such as digital control boards or analog control boards), print cartridges, fusers, and / or scanners, etc. Various of these hardware components can have settings that enable authorized functions of hardware components associated with a specific electronic device, for example, functions corresponding to business logic associated with the specific electronic device.
[0014] As a specific example and for purposes of illustration, an electronic device may have multiple hardware components and may maintain business logic settings for the hardware components. For example, a business may develop a product that is sold in multiple configurations, and some of the different configurations may be associated with different business logic (e.g., authorized functionality and / or licensed features, etc.) for a particular product. In this regard, for example, a product sold at a higher price point may have additional and / or different functionality enabled compared to a product sold at a lower price point.
[0015] A problem associated with such products may be that a low-priced product may be purchased and modified in an unauthorized manner, for example, by replacing hardware components in a device to overwrite business logic associated with the purchased product. The example devices, systems, methods, and computer-readable media of the present disclosure may enable business logic to be securely maintained across multiple higher-performance (and therefore relatively more expensive) hardware components, which may prevent, for example, purchasing a lower-performance model and then converting it to a higher-performance model by replacing hardware components.
[0016] In some examples, a device may include a first hardware component that includes a first memory and a first processor. The first processor may initiate pairing between the first hardware component and the second hardware component to establish a trust relationship between the first hardware component and the second hardware component. In response to a successful pairing between the first hardware component and the second hardware component, the processor may compare a first setting of the first hardware component with a second setting of the second hardware component. At this point, in response to determining that the second setting corresponds to the first setting, the processor may authorize operation of the second hardware component.
[0017] By enabling hardware components to pair to establish a trust relationship, the hardware components within the device can be implemented to securely maintain the predetermined functional configuration (such as secure business logic) of the device across multiple hardware components throughout the life of the product. The example device of the present disclosure can improve security by using the trust relationship between the hardware components to prevent the unauthorized replacement of the hardware components (by enabling one hardware component to prevent the operation of another unauthorized hardware component at each power-on). At this point, each hardware component can have a unique identity, and therefore the hardware component cannot be simply uninstalled from the first device and installed in the second device to replace the corresponding hardware component in the second device. In this way, the example device of the present disclosure can prevent the unauthorized conversion of the model of lower performance (e.g., lower price) to the model of higher performance (e.g., higher price) (e.g., by replacing the hardware components of the device). In some examples, the new hardware component can obtain authorization from the cloud service before the new hardware component can be installed on the device, thereby preventing unauthorized changes to the hardware component.
[0018] First refer to Figure 1 and Figure 2 . Figure 1 A block diagram of an example device 100 is shown that may include a first hardware component 102 that may initiate pairing with a second hardware component to establish a trust relationship and authorize operation of the second hardware component. Figure 2 shows that it can be included in Figure 1 1 is a block diagram of an example system 200 of an example device 100. It should be understood that in Figure 1 The device 100 depicted in and / or in Figure 2 The system 200 depicted in FIG. 2 may include additional features, and some of the features described herein may be removed and / or modified without departing from the scope of the device 100 and / or system 200 .
[0019] The device 100 may include a first hardware component 102, which may include a first processor 104 and a first memory 106. The device 100 may be a printer, a multifunction device, and / or a computing device such as a server, a node in a network (such as a data center), a personal computer, a laptop computer, a tablet computer, a smart phone, a gateway, a network router, and / or an electronic device such as an Internet of Things (IoT) device. As a specific example, the first hardware component 102 of the device 100 may be a component of a printer, including, for example, a control board (such as a digital control board and / or an analog control board, etc.), a cartridge, a fuser, and / or a laser scanner, etc. The second hardware component 202 may also be any of the components listed above, and may be similar to or different from the first hardware component 102.
[0020] Each of the processors 104 and 204 may be a semiconductor-based microprocessor, a central processing unit (CPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), and / or other hardware devices. Although the first hardware component 102 and the second hardware component 202 are depicted as having a single processor 104, 204, respectively, it should be understood that the hardware components 102, 202 and / or the device 100 may include additional processors and / or cores without departing from the scope of the hardware components 102, 202 and / or the device 100. In this regard, references to a single processor 104, 204 and a single memory 106, 206 may be understood to apply additionally or alternatively to multiple processors 104, 204 and multiple memories 106, 206.
[0021] The memory 106, 206 can be, for example, a non-volatile memory, such as a read-only memory (ROM), a flash memory, a solid-state drive, a random access memory (RAM), an electrically erasable programmable read-only memory (EEPROM), a storage device or an optical disk, etc. For example, the memory 106, 206 can be a non-volatile random access memory (NVRAM), which can be implemented to store and return data through a serial programmable interface (SPI) bus / connection. In some examples, the memory 106, 206 can be a dedicated memory integrated into, for example, a system on a chip (SoC) and / or a security chip, etc. that can provide enhanced security. In some examples, the memory 106, 206 can be soldered on a chip located on the corresponding hardware component 102, 202, respectively, and can be used for security and secure storage.
[0022] As in Figure 1 , the processor 104 may perform various operations 110 to 114 to authorize the operation of the second hardware component 202. The operations 110 to 114 may be hardware logic blocks that the processor 104 may execute. In other examples, the operations 110 to 114 may be machine-readable instructions (e.g., non-transitory computer-readable instructions). In other examples, the device 100 may include a combination of instructions and hardware logic blocks to implement or perform functions corresponding to the operations 110 to 114.
[0023] The processor 104 may perform operation 110 to start the first hardware component 102 and the second hardware component (such as Figure 2202) to establish a trust relationship between the first hardware component 102 and the second hardware component 202. In some examples, the second hardware component 202 can be installed in the device 100 together with the first hardware component 102, and can include a second processor 204 and a second memory 206. The first hardware component 102 and the second hardware component 202 can communicate via a communication protocol through a bus. In some examples, the first hardware component 102 and the second hardware component 202 can be arranged separately from each other, and can be connected to communicate with each other through a network 222.
[0024] The pairing process may include sharing identification information (such as Figure 2 102) and verify the shared identification information to establish a trust relationship between the first hardware component 102 and the second hardware component 202. As a specific example and for the purpose of illustration, the processor 104 may send the first device identity 214 associated with the first hardware component 102 to the second hardware component 202. In some examples, the first device identity 214 may include a first device identifier 216, which may uniquely identify the first hardware component 102. The first device identity 214 may include a first credential 218, which may be used to authenticate the first device identifier 216. In some examples, the first credential 218 may include an asymmetric public key, which may be built into the first hardware component 102 and used by the second hardware component 202 to verify the first device identity 214 of the first hardware component 102. In this regard, the first device identifier 216 may be an identifier that provides uniqueness and traceability to the corresponding hardware component. The first credential 218 may be a credential that provides cryptographic verification of authenticity and ownership.
[0025] The second processor 204 in the second hardware component 202 may verify the first device identity 214 at the second hardware component 202. In response to successfully verifying the first device identity 214 at the second hardware component 202, the processor 104 at the first hardware component 102 may receive a second device identity 224 associated with the second hardware component 202. The second device identity 224 may uniquely identify the second hardware component 202 and may include a second device identifier 226 and a second credential 228 associated with the second hardware component 202.
[0026] In some examples, the processor 104 can initiate verification to prove that the received second device identity 224 is associated with the second hardware component 202. In this regard, the processor 104 can authenticate ownership of the second device identity 224 by the second hardware component 202. The processor 104 can authenticate the second device identity 224 using the second device identifier 226 and the second credential 228, which can be unique to the second hardware component 202.
[0027] In some examples, the processor 104 may use information from a third hardware component (not shown) in addition to the information retrieved from the second hardware component 202 to authenticate the second device identity 224. For example, the processor 104 may initiate verification by using information unique to a plurality of hardware components to prove that the received second device identity 224 is associated with the second hardware component 202. In this regard, the processor 104 may prove ownership of the second device identity 224 based on an authentication key, which may be generated to include a unique authentication key associated with the third hardware component, a first credential 218 associated with the first hardware component 102, and / or a second credential 228 associated with the second hardware component 202. The third hardware component may be a hardware component installed in the device 100 similar to the first hardware component 102 and / or the second hardware component 202, such as a cartridge, a fuser, and / or a laser scanner, etc.
[0028] In response to successful verification of the second device identity 224 from the second hardware component 202, the processor 104 may establish a trust relationship between the first hardware component 102 and the second hardware component 202. In this regard, the trust relationship between the hardware components in the device 100 may be verified / established throughout the life of the device 100. For example, each time the first hardware component 102 and / or the second hardware component 202 is powered on, the processor 100 may initiate a pairing and verification process to establish a trust relationship between the first hardware component 102 and the second hardware component 202.
[0029] In some examples, in response to an unsuccessful pairing with the second hardware component 202, such as an unsuccessful verification or authentication based on the second device identity 224, the processor 104 may prevent operation of the second hardware component 202. In this regard, the processor 104 of the first hardware component 102 may withhold operating data and processes to render the second hardware component 202 inoperable. In some examples, the processor 104 of the first hardware component 102 may deny power and / or connectivity to the second hardware component 202, etc., to prevent operation of the second hardware component 202. Alternatively or additionally, the processor 104 of the first hardware component 102 may be unable to provide basic cryptographic material, such as the credentials 218, to allow normal operation.
[0030] In some examples, a hardware component may establish a trust relationship with another hardware component using a trust relationship formed with one hardware component. As a specific example, in addition to a trust relationship with the second hardware component 202, the first hardware component 102 may also have a trust relationship with a cloud service 212. The cloud service 212 may be a server, a computing device, and / or a group of computing devices that provide services to the device 100. In this regard, the processor 104 may enable the trust relationship to be inherited between the second hardware component 202 and the cloud service 212 based on the trust relationship between the first hardware component 102 and the second hardware component 202 and the trust relationship between the first hardware component 102 and the cloud service 212. In some examples, the processor 104 may enable the trust relationship between the second hardware component 202 and the cloud service 212 to be inherited without performing the previously described pairing and certification process by utilizing a known trust relationship.
[0031] In some examples, the second hardware component 202 can establish a trust relationship with the cloud service 212 without inheriting the trust relationship with the cloud service 212 from the first hardware component 102. In this regard, the second hardware component 202 can initiate pairing with the cloud service 212, including sharing and verifying the device identity and proving the shared device identity, as previously described with reference to pairing with the first hardware component 102. It should be understood that the second hardware component 202 can establish a trust relationship with multiple hardware components implemented in the device 100, or alternatively or additionally, the second hardware component 202 can establish a trust relationship with hardware components implemented in other devices on the network 222 through the network 222.
[0032] In response to the successful pairing between the first hardware component 102 and the second hardware component 202, the processor 104 may perform operation 112 to compare the first settings 220 of the first hardware component 102 with the second settings 230 of the second hardware component 202. In some examples, the first settings 220 may define the functionality of the first hardware component 102, and the second settings 230 may define the functionality of the second hardware component 202. The first settings 220 and the second settings 230 may be mirror copies of each other and may be written to a secure memory (such as the first memory 106 and the second memory 206) located on the respective hardware components.
[0033] As a specific example and for purposes of illustration, the first setting 220 may be implemented as a control bit that may be written to a secure memory of the first hardware component 102. In some examples, the first setting 220 may include a setting that allows a replaced hardware component to pair with other hardware components, or a setting that locks the first setting 220 of the first hardware component 102. In this regard, the first hardware component 102 may prevent pairing with unrecognized hardware components and / or prevent unauthorized replacement or installation of hardware components.
[0034] In some examples, first settings 220 may include settings that define authorized functionality of device 100 (e.g., functionality associated with intended business logic of device 100). As a specific example, where second hardware component 202 is replaced in device 100 and successfully paired with first hardware component 102, processor 104 may verify second settings 230 and may prevent operation of the new hardware component based on determining that the authorized functionality has been changed, e.g., where second settings 230 and first settings 220 associated with the authorized functionality do not match.
[0035] In some examples, processor 104 may verify first setting 220 against second setting 230 during a boot process of device 100. Based on a determination that first setting 220 does not correspond to second setting 230, processor 104 may prevent operation of second hardware component 202. In this regard, in response to determining that second setting 230 corresponds to first setting 220, processor 104 may perform operation 114 to authorize operation of second hardware component 202.
[0036] In some examples, as previously described, the second hardware component 202 can authorize operation of the first hardware component 102 in a manner similar to the first hardware component 102. For example, the second processor 204 can authorize operation of the first hardware component 102 based on the trust relationship determined by the second processor 204 and the verification of the first setting 220 and the second setting 230. For example, in response to successfully pairing with the first hardware component 102, the second processor 204 can compare the second setting 230 of the second hardware component 202 with the first setting 220 of the first hardware component 102.
[0037] In this case, in response to determining that the first setting 220 corresponds to the second setting 230, the second processor 204 may authorize operation of the first hardware component 102, and in response to determining that the pairing is unsuccessful or the first setting 220 is different from the second setting 230, the second processor 204 may prevent operation of the first hardware component 102. In some examples, the second processor 204 may determine that the first hardware component 102 is a new hardware component and may request the cloud service 212 to authorize the new hardware component. At this point, based on the authorization of the new hardware component from the cloud service 212, the second processor 204 may authorize operation of the new hardware component. In some examples, the cloud service 212 may include a priori information that provides information to the cloud service 212 to make a determination to authorize or deny a re-pairing request of the hardware component. The information stored in the cloud service 212 may allow the cloud service 212 to track the hardware components 102, 202, including modification, replacement, operation and / or status information, etc., and may ensure proper operation of the hardware components 102, 202.
[0038] In some examples, when a hardware component in the device 100 is replaced, the processor of the hardware component can determine which hardware component is an existing hardware component and which is a new hardware component. For example, the processor 104 can determine that the second hardware component 202 is a new hardware component based on the exchange of information (such as the first device identity 214 and the second device identity 224). At this point, the new hardware component can be installed in the device 100 and successfully paired with the first hardware component 102. In response to identifying the new hardware component, the processor 104 can request the cloud service 212 to authorize the new hardware component in the device 100, and based on the authorization from the cloud service 212, the processor 104 can authorize the operation of the new hardware component, for example, the device 100 can be authorized to print using the newly added hardware component.
[0039] As a specific example and for purposes of illustration, the processor 104 may determine that the second hardware component 202 is a new hardware component based on the second setting 230. In this regard, the second setting 230 may include a lock setting that may enable a lock state of the pairing information stored in the second memory 206. When the second setting 230 that enables the lock state of the pairing information in the second hardware component 202 is set, the processor 104 may obtain authorization from the cloud service 212 for re-pairing the second hardware component 202 determined to be a new hardware component to the first hardware component 102.
[0040] Although the device 100 is depicted as having two hardware components (specifically, the first hardware component 102 and the second hardware component 202), it should be understood that additional hardware components may be provided in the device 100 without departing from the scope of the hardware components 102, 202 and / or the device 100. In this regard, the plurality of hardware components may establish a network of paired hardware components. In this example, as previously described, the first hardware component 102 may establish multiple pairings with each of the plurality of hardware components and / or inherit trust relationships with specific hardware components.
[0041] Relative to Figure 3 The method 300 depicted in FIG. 1 , in which various ways in which the processors 104 , 204 may operate are discussed in greater detail. Figure 3 A flow chart of an example method 300 for initiating pairing between a first hardware component 102 and a second hardware component 202 to establish a trust relationship and for authorizing operation of the first hardware component 102 and / or the second hardware component 202 is depicted. Figure 3 The method 300 depicted in FIG. 300 may include additional operations, and some of the operations described therein may be removed and / or modified without departing from the scope of the method 300. For illustrative purposes, reference is made to FIG. Figure 1 and Figure 2 Method 300 is described with reference to the features depicted in FIG.
[0042] At block 302, the processor 104 may initiate pairing of the first hardware component 102 with the second hardware component 202. In this regard, the pairing may establish a trust relationship between the first hardware component 102 and the second hardware component 202.
[0043] In some examples, the processors 104, 204 can share the identity of the first hardware component 102 and the identity of the second hardware component 202 between the first hardware component 102 and the second hardware component 202. The identity of the first hardware component 102 (such as in Figure 2204 ) may include a first device identifier 216 and a first credential 218. Similarly, an identity of a second hardware component 202, such as a second device identity 224, may include a second device identifier 226 and a second credential 228. In this regard, the first device identifier 216 and the second device identifier 226 may be identifiers that provide uniqueness and traceability to the respective hardware components. The first credential 218 and the second credential 228 may be credentials that provide cryptographic verification of authenticity and ownership. The processor 104, 204 may initiate verification to prove the identity of the first hardware component 102 and the identity of the second hardware component 202. Based on determining that the identity of the first hardware component 102 and the identity of the second hardware component 202 are verified, the processor 104, 204 may establish a trust relationship between the first hardware component 102 and the second hardware component 202. In this way, each hardware component may have a unique identity that can be verified, and therefore the hardware component cannot be simply taken out of a first device (such as device 100) and installed in a second device that is different from the first device to replace the corresponding hardware component in the second device.
[0044] In some examples, the processor 104, 204 can generate an authentication key to verify the first hardware component 102 and the second hardware component 202. In this regard, the processor 104, 204 can generate the authentication key to include a unique authentication key associated with the third hardware component. In some examples, the authentication key can include a unique authentication key from the third hardware component, a first credential 218 associated with the first hardware component 102, and a second credential 228 associated with the second hardware component 202.
[0045] At block 304, in response to the successful pairing between the first hardware component 102 and the second hardware component 202 in block 302, the processor 104 may determine that the first setting 220 associated with the first function enabled in the first hardware component 102 matches the second setting 230, and the second setting 230 is associated with the second function enabled in the second hardware component 202. In this regard, the first function may be the same as the second function. In some examples, the first setting 220 may include the same set of settings as the second setting 230, and the first setting 220 may match the second setting 230 when each setting in the set of settings matches each other.
[0046] At block 306, based on determining that the first setting 220 matches the second setting 230, the processor 104 of the first hardware component 102 may authorize operation of the second hardware component 202. Additionally, at block 308, the second processor 204 of the second hardware component 202 may authorize operation of the first hardware component 102.
[0047] In some examples, the trust relationship between the hardware components in the device 100 can be verified / established throughout the life of the device 100. For example, each time the first hardware component 102 and / or the second hardware component 202 is powered on, the processor 100 can initiate a pairing and verification process to establish a trust relationship between the first hardware component 102 and the second hardware component 202.
[0048] In some examples, in response to an unsuccessful pairing between the first hardware component 102 and the second hardware component 202, or in response to determining that the first setting 220 does not match the second setting 230, the processor 104 can prevent operation of the second hardware component 202. Additionally or alternatively, the second processor 204 can prevent operation of the first hardware component 102.
[0049] In some examples, the processor 104 may cause a trust relationship to be established between the first hardware component 102 and the cloud service 212 by, for example, performing a pairing process between the first hardware component 102 and the cloud service 212. In addition, the processor 104 may establish a trust relationship to be inherited between the second hardware component 202 and the cloud service 212 based on the trust relationship between the first hardware component 102 and the second hardware component 202 and the trust relationship between the first hardware component 102 and the cloud service 212. In some examples, the processor 104 may establish a trust relationship between the second hardware component 202 and the cloud service 212 without performing a pairing process between the second hardware component 202 and the cloud service 212 by using other known trust relationships.
[0050] In some examples, one of the processors 104, 204 can determine that the first hardware component 102 or the second hardware component 202 is a new hardware component. At this point, the processor 104, 204 can request the cloud service 212 to authorize the installation of the new hardware component, and based on the authorization from the cloud service 212, a pairing can be established between the new hardware component and the remaining one of the first hardware component 102 and the second hardware component 202.
[0051] Some or all of the operations proposed in method 300 may be included as utilities, programs, or subroutines in any desired computer-accessible medium. In addition, method 300 may be implemented by a computer program, which may exist in various active and inactive forms. For example, they may exist as computer-readable instructions (including source code, object code, executable code, or other formats). Any of the above may be implemented on a non-transitory computer-readable storage medium.
[0052] Examples of non-transitory computer readable storage media include computer system RAM, ROM, EPROM, EEPROM, and magnetic or optical disks or tapes. It should therefore be understood that any electronic device capable of performing the functions described above can perform those functions listed above.
[0053] Now refer to Figure 4 , a block diagram of a non-transitory computer-readable medium 400 is shown, the medium 400 having computer-readable instructions stored thereon that authorize the operation of the first hardware component 102 and / or the second hardware component 202. It should be understood that in Figure 4 The computer-readable medium 400 depicted in the may include additional instructions, and some of the instructions described herein may be removed and / or modified without departing from the scope of the computer-readable medium 400 disclosed herein. The computer-readable medium 400 may be a non-transitory computer-readable medium. The term "non-transitory" does not include a transient propagation signal.
[0054] The computer readable medium 400 may have computer readable instructions 402-408 stored thereon, a processor (such as in Figure 1 to Figure 2 The processors 104, 204 depicted in the figure can execute computer readable instructions 402 to 408. The computer readable medium 400 can be an electronic, magnetic, optical or other physical storage device containing or storing executable instructions. The computer readable medium 400 can be, for example, a random access memory (RAM), an electrically erasable programmable read-only memory (EEPROM), a storage device or an optical disk, etc.
[0055] The processor may fetch, decode, and execute instructions 402 to share identification information between the first hardware component 102 and the second hardware component 202. The shared identification information may include a device identity 214, 224, which may include a device identifier 216, 226 and a credential 218, 228 to uniquely identify the respective hardware component 102, 202.
[0056] The processor may retrieve, decode, and execute instructions 404 to verify the identification information to establish a trust relationship between the first hardware component 102 and the second hardware component 202. In response to determining that a trust relationship has been established between the first hardware component 102 and the second hardware component 202, the processor may retrieve, decode, and execute instructions 406 to verify a first setting 220 of the first hardware component 102 associated with a first authorized functionality and a second setting 230 of the second hardware component 202 associated with a second authorized functionality.
[0057] In some examples, the first setting 220 associated with the first hardware component 102 and the second setting 230 associated with the second hardware component 202 can be the same. The processor can compare the first setting 220 to the second setting 230 to verify that the first setting 220 and the second setting 230 have been maintained.
[0058] In response to successful verification of the first setting 220 and the second setting 230, the processor can fetch, decode, and execute instructions 408 to authorize operation of the first hardware component 102 and / or the second hardware component 202. In some examples, in response to an unsuccessful pairing between the first hardware component 102 and the second hardware component 202, or in response to determining that the first setting 220 and the second setting 230 do not correspond to each other, the processor can prevent operation of the first hardware component 102 and / or the second hardware component 202.
[0059] Although representative examples of the present disclosure are described in detail throughout the present disclosure, the representative examples of the present disclosure have broad application, and the above discussion is not intended to and should not be construed as limiting but is provided as an illustrative discussion of various aspects of the present disclosure.
[0060] What has been described and illustrated herein are examples of the present disclosure and some of its variations. The terms, descriptions, and drawings used herein are presented by way of illustration and not limitation. Many variations are possible within the scope of the present disclosure, which is intended to be defined by the appended claims and their equivalents, in which all terms are intended to be given their broadest reasonable meanings unless otherwise indicated.
Claims
1. A device for pairing hardware components, comprising: The first hardware component includes: a first memory; and A first processor is configured to: Initiating pairing between the first hardware component and the second hardware component to establish a trust relationship between the first hardware component and the second hardware component; In response to a successful pairing between the first hardware component and the second hardware component, comparing a first setting of the first hardware component associated with a first authorized function with a second setting of the second hardware component associated with a second authorized function, the first authorized function being the same as the second authorized function; and In response to determining that the second setting corresponds to the first setting, operation of the second hardware component is authorized.
2. The device according to claim 1, comprising: The second hardware component comprises: a second memory; and A second processor is used to: In response to successfully pairing with the first hardware component, comparing the second setting of the second hardware component to the first setting of the first hardware component; and in response to determining that the first setting corresponds to the second setting, authorizing operation of the first hardware component; In response to determining that the pairing is unsuccessful or the first setting is different from the second setting, preventing operation of the first hardware component; and Determining that the first hardware component is a new hardware component, requesting a cloud service to authorize the new hardware component, and authorizing a new trust relationship and operation of the new hardware component based on the authorization of the new hardware component from the cloud service.
3. The device according to claim 1, wherein: The first processor is used for: In response to an unsuccessful pairing with the second hardware component, or in response to a determination that the second setting does not correspond to the first setting, operation of the second hardware component is prevented.
4. The device according to claim 1, wherein: To initiate the pairing, the first processor is configured to: sending a first device identity associated with the first hardware component to the second hardware component, the first device identity uniquely identifying the first hardware component; receiving, in response to verification of the first device identity at the second hardware component, a second device identity associated with the second hardware component, the second device identity uniquely identifying the second hardware component; initiating authentication to prove that the received second device identity is associated with the second hardware component; as well as In response to successful verification of the second device identity, the trust relationship is established between the first hardware component and the second hardware component.
5. The device according to claim 4, wherein: The first processor is used for: Verification is initiated based on an authentication key to prove that the received second device identity is associated with the second hardware component, wherein the authentication key is generated to include a unique authentication key associated with a third hardware component, a first credential associated with the first hardware component, and a second credential associated with the second hardware component.
6. The device according to claim 1, wherein: The first processor is further configured to: establishing a trust relationship between the first hardware component and the cloud service; and Based on the trust relationship between the first hardware component and the second hardware component and the trust relationship between the first hardware component and the cloud service, the trust relationship is enabled to be inherited between the second hardware component and the cloud service.
7. The device according to claim 1, wherein: The first processor is further configured to: determining that the second hardware component is a new hardware component; requesting the cloud service to authorize the new hardware component; and Based on the authorization from the cloud service, operation of the new hardware component is authorized.
8. A method for pairing hardware components, comprising: Initiating, by the processor, pairing of a first hardware component with a second hardware component, wherein the pairing establishes a trust relationship between the first hardware component and the second hardware component; In response to a successful pairing between the first hardware component and the second hardware component, determining, by the processor, that a first setting associated with a first authorized function enabled in the first hardware component matches a second setting associated with a second authorized function enabled in the second hardware component, the first authorized function being the same as the second authorized function; and Based on determining that the first setting matches the second setting, the first hardware component authorizing the operation of the second hardware component, and The operation of the first hardware component is authorized by the second hardware component.
9. The method according to claim 8, further comprising: In response to unsuccessful pairing between the first hardware component and the second hardware component, or in response to determining that the first setting does not match the second setting, the first hardware component prevents operation of the second hardware component and / or the second hardware component prevents operation of the first hardware component.
10. The method according to claim 8, further comprising: each time the first hardware component and / or the second hardware component are powered on, sharing the identity of the first hardware component and the identity of the second hardware component between the first hardware component and the second hardware component; initiating authentication to prove the identity of the first hardware component and the identity of the second hardware component; as well as The trust relationship is established between the first hardware component and the second hardware component based on determining that the identity of the first hardware component and the identity of the second hardware component are verified.
11. The method according to claim 10, further comprising: An authentication key is generated to authenticate the first hardware component and the second hardware component, the authentication key comprising a unique authentication key associated with a third hardware component, a first credential associated with the first hardware component, and a second credential associated with the second hardware component.
12. The method according to claim 8, further comprising: Based on the pairing process between the first hardware component and the cloud service, establishing a trust relationship between the first hardware component and the cloud service; as well as establishing a trust relationship to be inherited between the second hardware component and the cloud service based on the trust relationship between the first hardware component and the second hardware component and the trust relationship between the first hardware component and the cloud service, Wherein, the trust relationship between the second hardware component and the cloud service is established without a pairing process between the second hardware component and the cloud service.
13. The method according to claim 8, further comprising: determining that the first hardware component or the second hardware component is a new hardware component; Requesting the cloud service to authorize installation of the new hardware component; as well as Based on the authorization from the cloud service, a pairing is established between the new hardware component and a remaining one of the first hardware component and the second hardware component.
14. A non-transitory computer-readable medium having computer-readable instructions stored thereon, which when executed, cause a processor of a computing device to: sharing identification information between the first hardware component and the second hardware component; verifying the identification information to establish a trust relationship between the first hardware component and the second hardware component; In response to determining that the trust relationship has been established between the first hardware component and the second hardware component, verifying a first setting of the first hardware component associated with a first authorized function and a second setting of the second hardware component associated with a second authorized function, the first authorized function being the same as the second authorized function; as well as In response to successful verification of the first setting and the second setting, operation of the first hardware component and / or the second hardware component is authorized.
15. The non-transitory computer readable medium of claim 14, wherein: The instructions further cause the processor to: In response to an unsuccessful pairing between the first hardware component and the second hardware component, or in response to a determination that the first setting and the second setting do not correspond to each other, operation of the first hardware component and / or the second hardware component is prevented.
Citation Information
Patent Citations
Trust establishment between a trusted execution environment and peripheral devices
CN107409118A
Memory device and chip set processor pairing
US20090222910A1
Validation And / Or Authentication Of A Device For Communication With Network
US20110099361A1