A security authentication method, device and system

Through the combination of edge devices and management service platforms, the use of identity identification and application software credentials for security authentication is solved, and the problem of high cost of TPM/TCM chips is achieved, low-cost and high-accuracy edge device security authentication is achieved.

CN116346435BActive Publication Date: 2025-07-08SHENZHEN HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310207092.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-27
Publication Date
2025-07-08
Estimated Expiration
2043-02-27

AI Technical Summary

Technical Problem

In the existing edge device safety certification scheme, the TPM, TCM or TPCM chips are small in size and high in price, which increases the cost of safety certification of edge devices.

Method used

Through the combination of edge devices and management service platform, the identity identification of edge devices and the authentication credentials of application software are used for secure authentication, avoiding setting up TPM or TCM chips in edge devices.

Benefits of technology

It reduces the cost of security certification for edge devices and improves the accuracy of security certification, prevents application software from being tampered with, and ensures device legality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116346435B_ABST
    Figure CN116346435B_ABST
Patent Text Reader

Abstract

An embodiment of the present application provides a security authentication method, device and system. In this method, an edge device sends authentication credential data of at least one application software to be authenticated to a management service platform. The authentication credential data includes a second authentication credential and a first authentication credential. The first authentication credential of the first application software is generated based on the file of the first application software, and the first application software is any one of the at least one application software. The second authentication credential is related to the identity identifier of the edge device; the management service platform sends an authentication result to the edge device; the authentication result indicates whether the edge device is a secure device; it is a secure device when none of the at least one application software has been tampered with and the edge device is legitimate, otherwise it is an insecure device; the first application software has not been tampered with when the first authentication credential of the first application software is the same as the first standard credential stored in the management service platform; the edge device is legitimate when the second authentication credential is the same as the second standard credential stored in the management service platform.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of security authentication, and in particular, to a security authentication method, device, and system. Background Art

[0002] With the continuous development of technologies such as the Internet of Things, big data, and artificial intelligence, more and more devices are connected to the network through edge devices to achieve the connection between the device and the Internet of Things management platform. The method of accessing the network through edge devices can be used in scenarios such as data collection or edge computing. Due to the complex deployment environment on the edge device side, for example, in industries such as power, a large number of edge devices are in an unattended untrusted environment, so a series of attack surfaces will be exposed. Once the edge device itself is attacked or impersonated, the attacker can intrude into the management service platform, causing immeasurable losses. To avoid this situation, it is necessary to perform security authentication on the edge device.

[0003] Currently, the security authentication solutions for edge devices include the following: One is a solution with a trusted platform module (TPM) as the trusted root, which measures the startup process during the startup phase of the edge device's operating system. For example, starting from the chip, security authentication is performed step by step on the basic input output system (BIOS), operating system, and application components. Another is a solution that uses a trusted cryptography module (TCM) as the trusted root for measurement. There is also an improved solution that uses a trusted platform control module (TPCM) as the trusted root for measurement, which adds a protection component on the basis that the TCM can perform secure startup measurement.

[0004] Since the TPM chip, TCM chip, or TPCM chip is built into the edge device, there are relatively high requirements for the volume of these chips. Chips with a smaller volume are more expensive, increasing the cost of security authentication for edge devices. Summary of the Invention

[0005] Embodiments of this application provide a security authentication method, device, and system to reduce the cost of security authentication for edge devices.

[0006] In a first aspect, embodiments of this application provide a security authentication system, including:

[0007] The edge device first determines at least one application software to be authenticated, and then sends authentication credential data to the management service platform. The authentication credential data includes a second authentication credential and first authentication credentials corresponding to the at least one application software respectively; the first authentication credential corresponding to the first application software is generated based on the file of the first application software, and the first application software is any one of the at least one application software; the second authentication credential is related to the identity identifier of the edge device.

[0008] The management service platform first receives the authentication credential data sent by the edge device, and then sends an authentication result to the edge device.

[0009] With this design, the edge device sends its own identity identifier (second authentication credential) and the first authentication credentials of at least one application software to the management service platform, and then the management service platform performs security authentication on the edge device. In the embodiments of the present application, the security authentication of the edge device is achieved by combining the edge device with the management service platform and based on the identity identifier of the edge device and the first authentication credentials of at least one application software. In the embodiments of the present application, it is not necessary to set a TPM chip or a TCM chip in the edge device to achieve the security authentication of the edge device. Therefore, the cost of the security authentication of the edge device is reduced.

[0010] In some exemplary embodiments, the authentication result is used to indicate whether the edge device is a secure device; when none of the at least one application software on the management service platform has been tampered with and the edge device is legitimate, it is determined that the edge device is a secure device, otherwise, it is determined that the edge device is an insecure device.

[0011] With this design, based on whether the application software has been tampered with and whether the edge device is legitimate, it is determined whether the edge device is a secure device, ensuring the accuracy rate of the security authentication of the edge device.

[0012] In some exemplary embodiments, when the management service platform determines that the first authentication credential of the first application software is the same as the first standard credential of the first application software stored in the management service platform, it is determined that the first application software has not been tampered with; otherwise, it is determined that the first application software has been tampered with.

[0013] With this design, tampered application software can be detected. The accuracy rate of the security authentication of the edge device is ensured.

[0014] In some exemplary embodiments, when the management service platform determines that the second authentication credential is the same as the second standard credential of the edge device stored in the management service platform, it is determined that the edge device is legitimate; otherwise, it is determined that the edge device is illegitimate.

[0015] Through this design, illegal edge devices can be detected. Thereby, the accuracy rate of the security authentication of edge devices is ensured.

[0016] In some exemplary embodiments, the system further includes a secure storage device, which is connected to the edge device.

[0017] The edge device sends the first authentication credentials corresponding to the at least one application software to the secure storage device. For example, when starting the authentication process, the edge device can generate the first authentication credentials for each application software in sequence according to the startup order of the at least one application software, and send them to the secure storage device. The secure storage device stores the second authentication credentials of the edge device, and sequentially receives the first authentication credentials corresponding to the at least one application software from the edge device, and stores the received first authentication credentials corresponding to the at least one application software.

[0018] The edge device sends a credential reading instruction to the secure storage device. After receiving the credential reading instruction, the secure storage device sends authentication credential data to the edge device.

[0019] Through this design, each time the authentication of at least one application software is started, the credentials generated for these application software are stored in the secure storage device. It prevents the application software from being tampered with during the authentication process, thereby ensuring the security of the second authentication credentials and the first authentication credentials of the at least one application software, and further improving the accuracy rate of the security authentication of edge devices.

[0020] In some exemplary embodiments, the secure storage device encrypts and stores the received second authentication credentials and the first authentication credentials corresponding to the at least one application software.

[0021] Through this design, the secure storage device encrypts and stores the received second authentication credentials and the first authentication credentials of the at least one application software, preventing the first authentication credentials and the second authentication credentials from being stolen, and further improving the security of the second authentication credentials and the first authentication credentials.

[0022] In some exemplary embodiments, the secure storage device stores the received second authentication credentials and the first authentication credentials corresponding to the at least one application software.

[0023] When the secure storage device receives the credential reading instruction from the edge device, it first encrypts the stored second authentication credentials and the first authentication credentials corresponding to the at least one application software, and then sends the authentication credential data to the edge device.

[0024] With this design, every time the secure storage device sends authentication credential data, it is sent after encryption, preventing the theft of the first authentication credential and the second authentication credential, ensuring the security of the second authentication credential in the authentication credential data and the first authentication credentials respectively corresponding to at least one application software, and further improving the accuracy rate of secure authentication.

[0025] In an exemplary embodiment, the second authentication credential included in the authentication credential data and the first authentication credentials respectively corresponding to at least one application software are encrypted by the secure storage device.

[0026] With this design, the theft of the first authentication credential and the second authentication credential is prevented, ensuring the security of the second authentication credential and the first authentication credentials respectively corresponding to at least one application software, and further improving the accuracy rate of secure authentication.

[0027] In an exemplary embodiment, the management service platform decrypts the second authentication credential and the first authentication credentials respectively corresponding to at least one application software from the authentication credential data.

[0028] With this design, the management server platform sets a corresponding decryption method to decrypt the authentication credential data to obtain the second authentication credential and the first authentication credentials respectively corresponding to the at least one application software. Ensuring the security of the first authentication credential and the first authentication credential, and thus improving the accuracy rate of secure authentication of the edge device.

[0029] In an exemplary embodiment, the at least one application software includes at least one of operating system layer software, container layer software, or application layer software.

[0030] In an exemplary embodiment, the first authentication credential corresponding to the first application software is the encrypted value after encrypting the mirror file of the first application software.

[0031] With this design, the first authentication credential of the first application software is determined based on the mirror file of the first application software. Therefore, when the first application software is tampered with, it can be known through the software of the first application, ensuring the accuracy of the security verification of the first application software.

[0032] In an exemplary embodiment, the edge device and the secure storage device are connected by any one of the following connection methods: Universal Serial Bus (USB) connection, Near Field Communication (NFC) connection, Ethernet connection, and serial port connection.

[0033] With this design, it is ensured that the edge device and the secure storage device can communicate normally in various scenarios.

[0034] In a second aspect, an embodiment of the present application provides a secure authentication method, and the method includes:

[0035] The edge device first determines at least one application software to be authenticated, then sends authentication credential data to the management service platform, and finally receives the authentication result sent by the management service platform; the authentication credential data includes a second authentication credential and first authentication credentials respectively corresponding to the at least one application software; the first authentication credential corresponding to the first application software is generated based on the file of the first application software, and the first application software is any one of the at least one application software; the second authentication credential is related to the identity identifier of the edge device.

[0036] Through this method, the edge device sends its own identity identifier (second authentication credential) and the first authentication credentials of at least one application software to the management service platform, and then the management service platform performs security authentication on the edge device. In the embodiments of the present application, the edge device is combined with the management service platform, and security authentication of the edge device is achieved based on the identity identifier of the edge device and the first authentication credentials of at least one application software. In the embodiments of the present application, it is not necessary to set a TPM chip or a TCM chip in the edge device to achieve security authentication of the edge device. Therefore, the cost of security authentication of the edge device is reduced.

[0037] In some exemplary embodiments, the authentication result is used to indicate whether the edge device is a secure device;

[0038] When none of the at least one application software is tampered with and the edge device is legal, the edge device is a secure device; otherwise, the edge device is an insecure device.

[0039] In some exemplary embodiments, when the first authentication credential of the first application software is the same as the first standard credential of the first application software stored in the management service platform, it indicates that the first application software is not tampered with; when the second authentication credential is the same as the second standard credential of the edge device stored in the management service platform, it indicates that the edge device is legal.

[0040] In some exemplary embodiments, the edge device is connected to a secure storage device, and the method further includes:

[0041] The edge device stores the second authentication credential in the secure storage device, and stores the first authentication credentials respectively corresponding to the at least one application software in the secure storage device. For example, when the edge device starts the authentication process, it can generate the first authentication credentials of each application software in sequence according to the startup order of the at least one application software, and store the first authentication credentials of each application software in the secure storage device.

[0042] Before the edge device sends the authentication credential data to the management service platform, it reads the authentication credential data from the secure storage device.

[0043] In some exemplary embodiments, the second authentication credential included in the authentication credential data and the first authentication credential corresponding to at least one application software are encrypted by a secure storage device.

[0044] In some exemplary embodiments, any one of the following connection methods is adopted for connection between the edge device and the secure storage device: Universal Serial Bus (USB) connection, Near Field Communication (NFC) connection, Ethernet connection, and serial port connection.

[0045] In some exemplary embodiments, at least one application software includes at least one of operating system layer software, container layer software, or application layer software.

[0046] In some exemplary embodiments, the first authentication credential corresponding to the first application software is the encrypted value obtained by encrypting the mirror file of the first application software.

[0047] In a third aspect, an embodiment of the present application provides a security authentication method, and the method includes:

[0048] The management service platform first receives the authentication credential data sent by the edge device, and then sends an authentication result to the edge device; the authentication credential data includes a second authentication credential and the first authentication credential corresponding to at least one application software; the first authentication credential corresponding to the first application software is generated based on the file of the first application software, and the first application software is any one of the at least one application software; the second authentication credential is related to the identity identifier of the edge device.

[0049] Through this method, the edge device is used to send its own identity identifier (second authentication credential) and the first authentication credential of at least one application software to the management service platform, and then the management service platform performs security authentication on the edge device. In the embodiment of the present application, the security authentication of the edge device is implemented by combining the edge device and the management service platform and based on the identity identifier of the edge device and the first authentication credential of at least one application software. In the embodiment of the present application, it is not necessary to set a Trusted Platform Module (TPM) chip or a Trusted Cryptography Module (TCM) chip in the edge device to implement the security authentication of the edge device. Therefore, the cost of the security authentication of the edge device is reduced.

[0050] In some exemplary embodiments, the authentication result is used to indicate whether the edge device is a secure device; it further includes:

[0051] When the management service platform determines that none of the at least one application software has been tampered with and the edge device is legal, it determines that the edge device is a secure device; otherwise, it determines that the edge device is an insecure device.

[0052] In some exemplary embodiments, it further includes:

[0053] When the management service platform determines that the first authentication credential of the first application software is the same as the first standard credential of the first application software stored in the management service platform, it determines that the first application software has not been tampered with; otherwise, it determines that the first application software has been tampered with.

[0054] In some exemplary embodiments, it further includes:

[0055] When the management service platform determines that the second authentication credential is the same as the second standard credential of the edge device stored in the management service platform, it determines that the edge device is legitimate; otherwise, it determines that the edge device is illegitimate.

[0056] In some exemplary embodiments, before sending the authentication result to the edge device, the method further includes:

[0057] The management service platform decrypts the second authentication credential and the first authentication credentials corresponding to at least one application software respectively from the authentication credential data.

[0058] In some exemplary embodiments, at least one application software includes at least one of operating system layer software, container layer software, or application layer software.

[0059] In some exemplary embodiments, the first authentication credential corresponding to the first application software is the encrypted value after encrypting the mirror file of the first application software.

[0060] In a fourth aspect, an embodiment of the present application provides a secure storage device, which supports connection with an edge device and includes:

[0061] The communication module receives the first authentication credentials corresponding to at least one application software to be authenticated after the edge device starts the authentication process; the first authentication credential corresponding to the first application software is generated based on the file of the first application software, and the first application software is any one of the at least one application software.

[0062] The storage module stores the second authentication credential of the edge device and stores the received second authentication credential and the first authentication credentials corresponding to at least one application software. The second authentication credential is related to the identity identifier of the edge device.

[0063] When the communication module receives the credential reading instruction of the edge device, it sends the authentication credential data to the edge device; the authentication credential data includes the second authentication credential and the first authentication credentials corresponding to at least one application software respectively.

[0064] With this design, each time the edge device starts to authenticate at least one application software, the credentials of these application software will be generated and stored in the secure storage device. This prevents the application software from being tampered with during the authentication process, thus ensuring the security of the second authentication credential and the first authentication credential of at least one application software, and further improving the accuracy of the security authentication of the edge device.

[0065] In some exemplary embodiments, the encryption module encrypts the received second authentication credential and the first authentication credential corresponding to the at least one application software to obtain the authentication credential data.

[0066] With this design, it is prevented that the second authentication credential and the first authentication credential corresponding to the at least one application software are stolen, and further improves the security of the second authentication credential and the first authentication credential of at least one application software.

[0067] In some exemplary embodiments, when the encryption module receives the credential reading instruction of the edge device, it encrypts the second authentication credential and the first authentication credential corresponding to the at least one application software to obtain the authentication credential data.

[0068] With this design, each time the secure storage device sends the authentication credential data, it is sent in an encrypted manner, which ensures the security of the second authentication credential and the first authentication credentials corresponding to at least one application software in the authentication credential data, and further improves the accuracy of the security authentication.

[0069] In some exemplary embodiments, the first authentication credential corresponding to the first application software is the encrypted value after encrypting the mirror file of the first application software.

[0070] In a fifth aspect, an embodiment of the present application provides an edge device, including a processor and a memory. The memory stores program instructions, and the processor executes the program instructions to execute any one of the methods executed by the edge device in the second aspect above.

[0071] In a sixth aspect, an embodiment of the present application provides a management service platform, including a processor and a memory. The memory stores program instructions, and the processor executes the program instructions to execute any one of the methods executed by the management service platform in the third aspect above.

[0072] In a seventh aspect, an embodiment of the present application further provides a computer-readable storage medium. Software programs are stored in the storage medium, and when the software programs are read and executed by one or more processors, the methods provided by any one of the designs in any aspect can be implemented.

[0073] In an eighth aspect, the present application provides a computer program product. The computer program product includes computer instructions which, when executed by a computing device, cause the computing device to execute the methods provided in any of the foregoing aspects or any possible implementation manner in any of the foregoing aspects. The computer program product may be a software installation package. In the case where it is necessary to use the methods provided in any of the foregoing aspects or any possible implementation manner in any of the foregoing aspects, the computer program product may be downloaded and executed on the computing device.

[0074] In a ninth aspect, the present application further provides a computer chip. The chip is connected to a memory and is configured to read and execute a software program stored in the memory to execute the methods provided in any of the foregoing aspects or any possible implementation manner in any of the foregoing aspects. BRIEF DESCRIPTION OF THE DRAWINGS

[0075] Figures 1A - 1B is an architecture diagram of the security authentication system provided by an embodiment of the present application;

[0076] Figure 2 is one of the schematic flowcharts of the security authentication method provided by an embodiment of the present application;

[0077] Figure 3 is another schematic flowchart of the security authentication method provided by an embodiment of the present application;

[0078] Figure 4 is a schematic structural diagram of an edge device provided by an embodiment of the present application;

[0079] Figure 5 is one of the schematic diagrams of the security authentication device provided by an embodiment of the present application;

[0080] Figure 6 is another schematic diagram of the security authentication device provided by an embodiment of the present application;

[0081] Figure 7 is a schematic structural diagram of the secure storage device provided by an embodiment of the present application;

[0082] Figure 8 is a third schematic diagram of a security authentication device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0083] Hereinafter, some terms in the present application are explained to facilitate understanding by those skilled in the art.

[0084] 1), Edge device

[0085] It is a device that provides an entry point to the core network of an enterprise or service provider. Edge devices can be routers, routing switches, integrated access devices (IADs), multiplexers, metropolitan area network (MAN) access devices, and wide area network (WAN) access devices. Edge devices also provide connectivity to carrier and service provider networks.

[0086] Edge devices may support the conversion of one type of network protocol to another. For example, local area network (LAN) devices such as Ethernet and token ring, or x digital subscriber line (xDSL) devices may use an asynchronous transfer mode (ATM) backbone network to connect to other core networks. The ATM network sends data in cells and uses connection-oriented virtual circuits. The Internet Protocol (IP) network is packet-oriented. So if ATM is used as the core, packets must be encapsulated in cells and the destination address must be converted to a virtual circuit identifier. Some new types of optical fibers use passive optical network subscriber loops such as gigabit-capable pon (GPON), and edge devices are connected to Ethernet through mobile network backhaul.

[0087] 2) Management service platform

[0088] The management service platform is short for the computing resources provided for edge devices and refers to the integration of computing-related resources. The management service platform in this embodiment can be implemented by one or more servers, and the servers can be physical servers or cloud servers.

[0089] A physical server is a physical machine. Real central processing unit (CPU), memory, hard disk, and broadband and other resources can be used through a physical server.

[0090] A cloud server is used to provide services such as elastic computing, virtual network, data storage, database, etc. required for enterprise Internet technology (IT) in the form of Representational State Transfer Application Programming Interface (REST API) over the Internet. For example, it may include but is not limited to services provided by virtual private cloud (VPC), gateway services, firewall services, network address translation (NAT) services, cloud disks, elastic Internet Protocol address (EIP), cloud monitoring services, and various other cloud services provided by cloud providers.

[0091] 3) Security authentication

[0092] An activity in which a third party that can be fully trusted verifies whether a certain identified product or service meets specific standards or normative documents. If it is determined that the identified product or service meets the specific standards or normative documents, it is determined that the identified product or service passes the security authentication. If the identified product or service does not meet the specific standards, it is determined that the identified product or server fails the security authentication.

[0093] In the embodiments of the present application, the security authentication of the edge device verifies the hardware and application software of the edge device to ensure that the edge device is a legitimate device and that at least one application software in the edge device has not been tampered with.

[0094] Among them, hardware is short for computer hardware, which refers to the general term of various physical devices composed of electronic, mechanical, and optoelectronic components in a computer system. These physical devices form an organic whole according to the requirements of the system structure to provide a material basis for the operation of computer software. Application software is a collection of computer data and instructions organized in a specific order. Application software is divided into system software, application software, and middleware between the two. Application software does not only include computer programs that can run on a computer, but documents related to these computer programs are generally also considered part of the application software. The application software in the embodiments of the present application includes operating system layer software, container layer software, and application layer software.

[0095] Among them, the operating system layer software is usually the software layer closest to the hardware. It is mainly used to complete tasks such as resource scheduling and allocation, information access and protection, and coordination and control of concurrent activities. The operating system layer software is the foundation for the operation of other upper-layer software and provides strong support for system program designers such as compiler programs and database management systems. The container layer software represents the state after software installation, and each software running environment is independent and isolated. The application layer software is the software for performing a certain function.

[0096] 4), Image file

[0097] It is a form of file storage and a type of redundancy. That is, there is an exact same copy of the data on one disk on another disk, which is called a mirror. Common image file formats include but are not limited to International Organization for Standardization (ISO), Binary (BIN), img format (IMG), and Data Access Object (DAO).

[0098] 5), TPM

[0099] It is a chip implanted inside a computer to provide a trusted root for the computer. The specifications of this chip are formulated by the Trusted Computing Group (TCG). It can effectively protect personal computers (PCs) and prevent unauthorized users from accessing. The Trusted Cryptography Module (TCM) researched in China corresponds to it.

[0100] 6), Trusted Computing Group

[0101] It is an organization composed of Advanced Micro Devices (AMD), Hewlett-Packard, International Business Machines Corporation (IBM), Intel, and Microsoft. Its aim is to establish the concept of trusted computing for personal computers. Its purpose is to widely use trusted computing platforms supported by hardware security modules in computing and communication systems to improve overall security. The Trusted Computing Group has formulated the standards for trusted platform modules, and many security chips comply with this specification. Moreover, due to its hardware implementation of security protection, it is gradually becoming a standard configuration for personal computers (PCs), especially portable PCs.

[0102] 7), TCM

[0103] It is a hardware module of the trusted computing platform, which provides cryptographic operation functions for the trusted computing platform and has a protected storage space.

[0104] 8), TPCM

[0105] The protection component assembly integrated in the trusted computing node is composed of hardware, software and firmware. It is connected in parallel with the hardware, software and firmware of the computing component. The trusted platform control module is a basic core module for establishing and guaranteeing the trust source point, and provides functions such as active measurement, active control, trusted verification, encryption protection, trusted reporting and cryptographic call for the trusted computing node.

[0106] 9), at least one

[0107] It means one or more.

[0108] 10), "and / or"

[0109] It is used to describe the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after.

[0110] In addition, it should be understood that in the description of this application, terms such as "first" and "second" are only used for the purpose of distinguishing descriptions, and cannot be understood as indicating or implying relative importance, nor can they be understood as indicating or implying order.

[0111] The present application will be introduced in detail below with reference to the accompanying drawings and embodiments.

[0112] Figure 1A It shows the schematic architecture diagram of the security authentication system applicable to the embodiments of the present application.

[0113] As Figure 1A shown, the security authentication system may include a management service platform 110 and edge devices 120. The management service platform in the embodiments of the present application can be provided by a security authentication manufacturer, and of course, it can also be provided by other manufacturers. The present application does not make any limitations in this regard.

[0114] The management service platform 110 can be connected and communicate with the edge devices 120 through a secure communication protocol (such as the transport layer security protocol, the packet transport layer security protocol, etc.). The management service platform 110 is used to provide authentication services for the edge devices 120, such as the authentication of the legality of the edge devices 120 and the authentication of whether the application software in the edge devices 120 has been tampered with.

[0115] In a possible example, a user of the edge device 120 can register an account on the management service platform 110, and this account has the qualification for the security authentication of purchasing (including different payment forms such as ordering or renting) the edge device. In the case of successful purchase of the security authentication qualification, the edge device 120 can generate a voucher (hereinafter referred to as the second standard voucher) for subsequent authentication of the legal use of the device based on its own identity identifier, and send this second standard voucher to the management service platform 110. The edge device 120 can also generate a voucher (hereinafter referred to as the first standard voucher) for subsequent verification of whether each application software has been tampered with, and send the first standard vouchers of each application software to the management service platform 110. It can be understood that after the above process, the edge device has the qualification for security authentication. In some embodiments, when the edge device 120 deploys new application software, it can send the first standard voucher of the deployed application software to the management service platform 110.

[0116] In another possible example, the management service platform 110 can provide different application software authentication services. The first standard vouchers of each application software are stored in the management service platform 110. For example, the standard vouchers for verifying whether each application software has been tampered with can be stored in the management service platform by the manufacturers of each application software. When the edge device 120 deploys application software, it does not need to send the first standard voucher of the application software to the management service platform 110. When a certain application software is deployed in the edge device 120, it can use the authentication service of this application software provided by the management service platform 110.

[0117] When the edge device 120 starts the authentication process, the edge device 120 can generate an authentication voucher for verifying the legality of the edge device and generate authentication vouchers for each application software based on the files of each application software to be verified respectively. And send each authentication voucher to the management service platform 110 for authentication. The specific authentication method will be described in detail later and will not be elaborated here.

[0118] In the embodiments of the present application, the management service platform 110 may be implemented by one or more servers, which may be physical servers or cloud servers. A physical server is a physical machine. Real resources such as a central processing unit (CPU), memory, hard disk, and broadband can be used through a physical server. A cloud server is used to provide services such as elastic computing, virtual network, data storage, and database required for enterprise Internet technology based on the Internet in the form of REST APIs. For example, it may include but is not limited to services provided by private networks, gateway services, firewall services, network address translation services, cloud disks, elastic public network Internet protocols, cloud monitoring services, and other cloud services provided by various cloud providers. The embodiments of the present application do not limit the management service platform. The management service platform 110 may include at least one security authentication service providing module, and the at least one security authentication service providing module can be used to provide corresponding services for edge devices to achieve security authentication of edge devices.

[0119] It should be noted that the above is only an example illustration of the interaction between the management service platform and edge devices and / or the implementation of device-related functions, rather than any limitation. In specific implementations, the interaction between devices may not be limited to the above interaction methods, and the implementation of device-related functions is also not limited to the above description. The present application does not limit this.

[0120] Figure 1B It is a schematic structural diagram of another security authentication system provided by the embodiments of the present application. Refer to Figure 1B As shown, in addition to the management service platform 110 and edge devices 120, the security authentication system further includes a security storage device 130. The security storage device 130 is connected to the edge device 120. The connection methods between the security storage device 130 and the edge device 120 include but are not limited to Universal Serial Bus (USB) connection, near-field wireless communication connection, Ethernet connection, and serial port connection. The security storage device 130 is used to store a second authentication credential for verifying the legitimacy of edge devices and a first authentication credential for verifying whether each application software has been tampered with. The specific storage method will be described in detail later and will not be elaborated here.

[0121] In some embodiments, the security storage device 130 may include a communication interface (which may also be referred to as a communication module) and a storage module. The communication interface is used to connect to edge devices. The communication interface can be, for example, a USB interface, a near-field wireless communication interface, an Ethernet interface, a serial port, etc. The storage module is used to store the authentication credentials of the edge device 120. The specific functions of the security storage device will be described in detail later and will not be elaborated here.

[0122] The following describes in detail the security authentication method flow provided by the embodiments of the present application in combination with the above security authentication system structure.

[0123] Refer to Figure 2 As shown, it is a schematic flowchart of a security authentication method provided by the embodiments of the present application. Figure 2 The provided security authentication method is described in combination with Figure 1A the security authentication system shown. It can be understood that the interaction process between the edge device and the management server platform is shown in this method flowchart. The edge device and the management server platform are the Figure 1A edge device and management server platform in Figure 2 As shown, the method includes the following steps:

[0124] S210: After the edge device starts the authentication process, determine at least one application software to be authenticated.

[0125] In the embodiments of the present application, starting and executing the authentication process in the edge device can be achieved by installing a corresponding application program (APP) with security authentication. When developing the APP, the developer of the APP can configure the security authentication function for the APP (i.e., the security authentication function of the edge device). The user registers the edge device on the management service platform through the APP to start the authentication process. Moreover, the way to start the authentication process in S210 of the present application can be configured as automatic trigger enablement, manual trigger enablement, or other trigger enablement methods, and the present application does not limit this. As an example, if the start method is configured as automatic trigger enablement, the APP corresponding to the security authentication function can be installed on the edge device, and relevant configurations for automatic trigger start can be set in the APP. For example, when the edge device is powered on, etc. If the start method is configured as manual trigger enablement, it can be considered that when the APP is installed on the edge device and the user on the edge device side manually sets and enables the relevant configuration items, it is considered that the method in S210 needs to be executed, that is, the authentication process in the embodiments of the present application is started. The at least one application software to be authenticated in the embodiments of the present application can be pre-configured.

[0126] In a possible implementation manner, the at least one application software in S210 includes at least one of other layer software such as operating system layer software, container layer software, and application layer software.

[0127] It should be noted that: in this embodiment, at least one application software can be set according to the actual situation, and is not limited to the application software described above. For example, it may also include system boot layer software. This embodiment does not limit at least one application software here. Moreover, the number of operating system layer software in the embodiments of the present application can be one or more, the number of container layer software can be one or more, and the number of application layer software can be one or more. This embodiment does not make a limitation.

[0128] S220: The edge device sends authentication credential data to the management service platform. The authentication credential data includes a second authentication credential and first authentication credentials corresponding to at least one application software respectively. The first authentication credential corresponding to the first application software is generated based on the file of the first application software. The first application software is any one of the at least one application software. The second authentication credential is related to the identity identifier of the edge device.

[0129] In the embodiments of the present application, the first authentication credential corresponding to the first application software is the encrypted value after encrypting the image file of the first application software. This encrypted value is obtained by encrypting the image file of the first application software using a pre-configured encryption algorithm. For example, this encryption algorithm can be a hash algorithm, and the corresponding encrypted value is a hash value. The embodiments of the present application do not limit the encryption algorithm, and the encryption algorithm can be set according to the actual situation.

[0130] Exemplarily, the second authentication credential in the embodiments of the present application is the identity identifier of the edge device pre-set in the edge device or the encrypted value obtained after encrypting the identity identifier. This identity identifier can be the media access control (MAC) address of the edge device. It can also be a credential obtained by performing a uniqueness calculation based on the MAC address of the edge device. It can also be a random unique identifier, and this random unique identifier can be obtained through a pre-configured related algorithm, such as the snowflake algorithm, etc. As an example, when the edge device installs an APP with a security authentication function, this APP generates an identity identifier for the edge device using a pre-configured identity identifier generation algorithm, and this identity identifier is used to identify the edge device. However, this identity identifier is unique. The embodiments of the present application do not limit the method for generating the identity identifier, and it can be configured according to the specific actual situation.

[0131] S230: The management service platform determines the authentication result based on the second authentication credential and the first authentication credentials corresponding to at least one application software respectively.

[0132] In the embodiments of the present application, the authentication result is used to indicate whether the edge device is a secure device.

[0133] In a possible implementation, when none of the at least one application software is tampered with and the edge device is legal, the edge device is a secure device; otherwise, the edge device is an insecure device.

[0134] Next, taking the manner of determining whether the first application software among the at least one application software is tampered with as an example, the manner of determining whether the at least one application software is tampered with will be described. In the embodiments of the present application, the manner of determining whether the other application software among the at least one application software is tampered with is the same as the manner of determining whether the first application software is tampered with, and both are determined by using the first authentication identifier of the application software itself. The embodiments of the present application will not elaborate on the determination manner of other application software.

[0135] In a possible implementation, the management service platform determines whether the first application software is tampered with and whether the edge device is legal through the following manner:

[0136] (1) Determine whether the first application software is tampered with: When the first authentication credential of the first application software is the same as the first standard credential of the first application software stored in the management service platform, it indicates that the first application software is not tampered with. When the first authentication credential of the first application software is different from the first standard credential of the first application software stored in the management service platform, it indicates that the first application software is tampered with.

[0137] In the embodiments of the present application, the first authentication credential of the first application software may be generated after the edge device starts the security authentication process. The first standard credential of the first application software may be sent to the management service platform for storage when the edge device is registered, or may be pre-configured in the management service platform by other devices, such as configured in the management service platform by the management server of the application software. The determination manner of the first authentication credential and the first standard credential is the same. However, the determination timing of the first authentication credential and the first standard credential is different.

[0138] (2) Determine whether the edge device is legal: When the second authentication credential is the same as the second standard credential of the edge device stored in the management service platform, it indicates that the edge device is legal. When the second authentication credential is different from the second standard credential of the edge device stored in the management service platform, it indicates that the edge device is illegal.

[0139] Similarly, the second authentication credential in the embodiments of the present application may be obtained after the edge device starts the security authentication process. The second standard credential may be obtained when the edge device registers with the management service platform, and the first standard credential is sent to the management service platform for storage. Among them, the determination manner of the first authentication credential and the second standard credential is the same. It's just that the acquisition timing is different.

[0140] S240: The management service platform sends the authentication result to the edge device.

[0141] In the embodiments of the present application, the authentication result indicates whether the edge device is a secure device, and can be indicated in any of the following ways:

[0142] Indication method 1: Indicate that the security authentication is passed.

[0143] For example, when each application software has not been tampered with and the edge device is legal, the authentication result may include indication information for indicating that the security authentication is passed. The edge device passes the security authentication, that is, the edge device is a secure device.

[0144] Indication method 2: Indicate that the security authentication fails.

[0145] For example, when there is tampered application software and / or the edge device is illegal among each application software, the authentication result may include indication information for indicating that the security authentication fails. The edge device fails the security authentication, that is, the edge device is an insecure device.

[0146] Indication method 3: Only indicate that the edge device is illegal.

[0147] As an example, the authentication result may include indication information for indicating that the edge device is illegal. As another example, the authentication result may carry the second authentication credential of the edge device, which means that the edge device is illegal. Of course, the authentication result may also not carry any data. As long as the edge device receives the authentication result, it can be determined that the edge device is illegal. In some embodiments, when the management service platform determines that the edge device is illegal, it may also not send the authentication result to the edge device. If the edge device does not receive the authentication result sent by the management service platform within the specified duration, it can be determined that the edge device is an insecure device.

[0148] In order to save computing resources, in a possible implementation manner, after determining that the edge device is illegal, the management service platform may not perform security authentication on each application software in the edge device.

[0149] Indication method 4: Indicate that the edge device is illegal and the application software that passes the security authentication.

[0150] As an example, the authentication result may carry the identifier of the application software that passes the security authentication and indication information indicating that the edge device is illegal.

[0151] Indication method 5: Indicate that the edge device is legal and the application software that fails the security authentication.

[0152] As an example, the identity of the application software that fails the security authentication can be carried in the authentication result. In some embodiments, the authentication result can also carry indication information indicating the legality of the edge device.

[0153] Figure 3 It is a schematic flowchart of another security authentication method provided by the embodiments of this application. Figure 3 The provided security authentication method is described in combination with Figure 1B the security authentication system shown. It can be understood that the interaction process between the edge device and the secure storage device and the management server platform is shown in the flowchart of this method. The edge device, the secure storage device, and the management server platform are Figure 1B the edge device, the secure storage device, and the management server platform in Figure 3 shown. As

[0154] S310: After the edge device starts the authentication process, determine at least one application software to be authenticated.

[0155] In the embodiments of this application, the at least one application software to be authenticated in S310 is the same as that in S210, and both are pre-configured. Moreover, the way to start the authentication process in S310 is the same as that in S210, so details are not described herein again.

[0156] S320: The edge device sequentially sends the first authentication credentials corresponding to the at least one application software to the secure storage device in the startup order of the at least one application software. The first authentication credential corresponding to the first application software is generated based on the file of the first application software. The first application software is any one of the at least one application software.

[0157] In the embodiments of this application, there is a corresponding secure storage device for each edge device. The secure storage device is connected to the edge device, and the connection methods include but are not limited to: Universal Serial Bus (USB) connection, short-range wireless communication connection, Ethernet connection, and serial port connection. As an example, the short-range wireless communication connection can be: wireless fidelity (WIFI), Bluetooth, ultra wide band (UWB), ZigBee protocol, and near field communication (NFC), etc.

[0158] As an example, the startup sequence of the at least one application software is in turn: operating system layer software, container layer software, application layer software. As Figure 4As shown in the figure, it is a schematic structural diagram of an edge device in an embodiment of the present application. The edge device includes a chip, a system boot layer software, an operating system layer software, a container layer software, and an application layer software. After the edge device is powered on, the startup sequence of each application software in the edge device is as follows: chip, system boot layer software, operating system layer software, container layer software, application layer software.

[0159] In a specific implementation, in S320, the system boot layer software includes the firmware for system startup, such as bios. The system boot layer software measures the operating system layer software to obtain the first authentication credential of the operating system layer software. And sends the first authentication credential of the operating system layer software to the secure storage device for storage. Then the system boot layer software starts the operating system layer software. After the operating system layer software starts, the operating system layer software measures the container layer software to obtain the first authentication credential of the container layer software. And sends the first authentication credential of the container layer software to the secure storage device for storage. Then the operating system layer software measures the application layer software to obtain the first authentication credential of the application layer software, and sends the first authentication credential of the application layer software to the secure storage device for storage. The operating system layer software starts the container layer software and the application layer software.

[0160] It should be noted that: the startup sequence of the at least one application software in the embodiment of the present application can be set according to the actual situation, and this embodiment does not limit the startup sequence of the at least one application software.

[0161] S330: The secure storage device stores the second authentication credential of the edge device and the first authentication credential corresponding to the at least one application software to obtain authentication credential data. The second authentication credential is related to the identity identifier of the edge device.

[0162] In some embodiments, the edge device can send the second authentication credential to the secure storage device for storage after the first startup authentication process, and does not need to repeat sending in subsequent authentication processes. Or, the edge device can send the obtained second authentication credential to the secure storage device for storage after each startup authentication process, and after the authentication process, notify the secure storage device to delete the stored second authentication credential. The storage method of the second authentication credential is not limited in this embodiment.

[0163] In the embodiments of the present application, the secure storage device may encrypt and store the first authentication credential and the second authentication credential, or may not encrypt and store them. The embodiments of the present application do not limit the storage method of the secure storage device. If the storage method of the secure storage device is encrypted storage, the secure storage device may pre-configure relevant encryption algorithms to encrypt the first authentication credential and the second authentication credential of at least one received application software. The embodiments of the present application do not limit the encryption algorithm here. As an example, the encryption algorithm may be SM2 encryption algorithm, AES (Advanced Encryption Standard) algorithm, ECC (Elliptic curve cryptography) and the like.

[0164] In step S330, when the secure storage device performs encrypted storage, it may adopt any of the following methods.

[0165] The first possible implementation method:

[0166] After the secure storage device receives the first authentication credential corresponding to the at least one application software, it encrypts and stores the first authentication credential corresponding to the at least one application software.

[0167] In some embodiments, the edge device sequentially sends the first authentication credential corresponding to the at least one application software to the secure storage device according to the startup order of the at least one application software. The secure storage device may encrypt and store one first authentication credential each time it receives one. In other embodiments, the secure storage device may also perform unified encrypted storage on the first authentication credentials of all application software after receiving the first authentication credentials of all application software sent by the edge device.

[0168] Further, after the secure storage device receives the credential reading instruction sent by the edge device, it may read the first authentication credential of each encrypted application software and the encrypted second authentication credential to obtain the authentication credential data. The second authentication credential and each first authentication credential included in the authentication credential data are encrypted. Then, the authentication credential data is sent to the edge device.

[0169] The second possible implementation method:

[0170] The secure storage device may store the first authentication credential corresponding to the at least one received application software. After receiving the credential reading instruction sent by the edge device, it encrypts the stored second authentication credential and the first authentication credential of each application software.

[0171] In some embodiments, after the secure storage device receives the credential reading instruction sent by the edge device, it encrypts the first authentication credentials of each stored application software respectively. In other embodiments, after the secure storage device receives the credential reading instruction sent by the edge device, it uniformly encrypts the first authentication credentials of all application software.

[0172] Further, after the secure storage device performs the encryption operation, it can read the first authentication credentials of each encrypted application software and the encrypted second authentication credentials to obtain the authentication credential data.

[0173] S340: The edge device sends a credential reading instruction to the secure storage device.

[0174] S350: Based on the received credential reading instruction, the secure storage device sends the authentication credential data to the edge device.

[0175] In the embodiments of the present application, the second authentication credential included in the authentication credential data and the first authentication credentials corresponding to at least one application software are encrypted by the secure storage device.

[0176] S360: The edge device sends the received authentication credential data to the management service platform.

[0177] S370: The management service platform decrypts the second authentication credential and the first authentication credentials corresponding to the at least one application software from the authentication credential data.

[0178] In the embodiments of the present application, the management service platform is pre-configured with relevant decryption algorithms, and the decryption algorithms correspond to the encryption algorithms in the secure storage device. The decryption algorithms are used to decrypt the second authentication credential and the first authentication credentials corresponding to the at least one application software in the authentication credential data. The decryption algorithms are not limited herein.

[0179] S380: The management service platform determines the authentication result based on the second authentication credential and the first authentication credentials corresponding to the at least one application software, and the authentication result is used to indicate whether the edge device is a secure device.

[0180] It should be noted that the method for determining whether the edge device is a secure device in S380 is the same as the method introduced in S230, and will not be elaborated herein.

[0181] S390: The management service platform sends the authentication result to the edge device.

[0182] The above mainly introduces the security authentication solution provided by this application from the perspective of the interaction between the secure storage device, the edge device, and the management service platform. It can be understood that, in order to implement the above functions, the secure storage device, the edge device, and the management service platform include the corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should easily realize that, in combination with the units and algorithm steps of each example described in the embodiments disclosed in this article, the present invention can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0183] Based on the same inventive concept as the method embodiment, the embodiment of this application also provides a security authentication device for executing the method performed by the edge device in the above-mentioned method embodiment. For related features, reference can be made to the above method embodiment and will not be elaborated here. The security authentication device 500 is applied to the edge device. For example, the security authentication device 500 can be the edge device, or the security authentication device is a chip or a chip system in the edge device. As Figure 5 shown, the security authentication device 500 includes a communication unit 510 and a processing unit 520. The processing unit 520 can be used to control the actions of the security authentication device 500, and the communication unit 510 can be used to support the communication between the security authentication device 500 and other network entities. Among them:

[0184] The processing unit 520 is used to determine at least one application software to be authenticated; the communication unit 510 is used to send authentication credential data to the management service platform, and the authentication credential data includes a second authentication credential and first authentication credentials corresponding to at least one application software respectively. The first authentication credential corresponding to the first application software is generated based on the file of the first application software, and the first application software is any one of the at least one application software. The second authentication credential is related to the identity identifier of the edge device; the communication unit 510 is further used to receive the authentication result sent by the management service platform; wherein, the authentication result is used to indicate whether the edge device is a secure device; when none of the at least one application software has been tampered with and the edge device is legal, the edge device is a secure device; otherwise, the edge device is an insecure device; when the first authentication credential of the first application software is the same as the first standard credential of the first application software stored in the management service platform, it indicates that the first application software has not been tampered with; when the second authentication credential is the same as the second standard credential of the edge device stored in the management service platform, it indicates that the edge device is legal.

[0185] In some exemplary embodiments, the edge device is connected to a secure storage device. The communication unit 510 is further configured to store the second authentication credential in the secure storage device, and sequentially store the first authentication credentials corresponding to the at least one application software in the secure storage device according to the startup sequence of the at least one application software; before sending the authentication credential data to the management service platform, read the authentication credential data from the secure storage device.

[0186] In some exemplary embodiments, the second authentication credential and the first authentication credentials corresponding to the at least one application software included in the authentication credential data are encrypted by the secure storage device.

[0187] In some exemplary embodiments, the edge device and the secure storage device are connected by any one of the following connection methods: Universal Serial Bus (USB) connection, Near Field Communication (NFC) connection, Ethernet connection, and serial port connection.

[0188] In some exemplary embodiments, the at least one application software includes at least one of operating system layer software, container layer software, or application layer software.

[0189] In some exemplary embodiments, the first authentication credential corresponding to the first application software is the mirror file of the first application software or the encrypted value obtained by encrypting the mirror file of the first application software.

[0190] Based on the same inventive concept as the method embodiments, the embodiments of the present application further provide another security authentication device for performing the method executed by the management service platform in the method embodiments shown above. For related features, reference can be made to the above method embodiments and will not be elaborated here. The security authentication device 600 is applied in the management service platform. For example, the security authentication device 600 may be the management service platform, or the security authentication device is a chip or a chip system in the management service platform. As Figure 6 shown, the security authentication device 600 includes a communication unit 610 and a processing unit 620. The processing unit 620 can be used to control the actions of the security authentication device 600, and the communication unit 610 can be used to support the communication between the security authentication device 600 and other network entities.

[0191] Among them, the communication unit 610 is configured to receive the authentication credential data sent by the edge device; the authentication credential data includes a second authentication credential and first authentication credentials respectively corresponding to at least one application software. The first authentication credential corresponding to the first application software is generated based on the file of the first application software, and the first application software is any one of the at least one application software. The second authentication credential is related to the identity identifier of the edge device. The communication unit 610 is further configured to send an authentication result to the edge device, where the authentication result is used to indicate whether the edge device is a secure device. When none of the at least one application software is tampered with and the edge device is legitimate, the edge device is a secure device; otherwise, the edge device is an insecure device. When the first authentication credential of the first application software is the same as the first standard credential of the first application software stored in the management service platform, it indicates that the first application software is not tampered with. When the second authentication credential is the same as the second standard credential of the edge device stored in the management service platform, it indicates that the edge device is legitimate.

[0192] In some exemplary embodiments, before sending the authentication result to the edge device, the processing unit 620 is configured to decrypt the second authentication credential and the first authentication credentials respectively corresponding to the at least one application software from the authentication credential data.

[0193] In some exemplary embodiments, the at least one application software includes at least one of operating system layer software, container layer software, or application layer software.

[0194] In some exemplary embodiments, the first authentication credential corresponding to the first application software is the image file of the first application software or the encrypted value obtained by encrypting the image file of the first application software.

[0195] It should be noted that the division of units in the embodiments of the present application is illustrative only, and is merely a logical function division. In actual implementation, there may be other division methods. In the embodiments of the present application, the various functional units may be integrated into one processing unit, or each unit may exist physically alone, or two or more units may be integrated into one unit. The above integrated units may be implemented in the form of hardware or in the form of software functional units.

[0196] Through the above method, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, through the above method, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded or executed on a computer, the processes or functions according to the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that the computer can access or a data storage device such as a server or data center that contains one or more collections of available media. The available media can be magnetic media (such as floppy disks, hard disks, magnetic tapes), optical media (such as DVDs), or semiconductor media. The semiconductor media can be a solid state drive (SSD).

[0197] Based on the same inventive concept as the method embodiment. As Figure 7 shown, it is a schematic structural diagram of a secure storage device provided by the present application. It can be seen from Figure 7 this that the secure storage device 700 includes a communication module 710, a storage module 720, and an encryption module 730.

[0198] Among them, the communication module 710 is used to receive a first authentication credential corresponding to at least one application software to be authenticated. The storage module 720 is used to store the second authentication credential of the edge device and the first authentication credential corresponding to the at least one application software. The encryption module 730 is used to encrypt the second authentication credential and the first authentication credential corresponding to the at least one application software. The communication module 710 is also used to send the authentication credential data obtained by encrypting the second authentication credential and the first authentication credential corresponding to the at least one application software to the edge device after receiving the credential reading instruction of the edge device.

[0199] It should be noted that the above is only an illustrative example of the implementation of the related functions of the secure storage device and is not any limitation. In specific implementation, the implementation of the device-related functions is not limited to the above description, and the present application does not make any limitation in this regard.

[0200] As Figure 8As shown in the figure, it is a schematic diagram of another security authentication device 800 provided by the present application. The security authentication device 800 can be applied to edge devices, or to management service platforms, or to secure storage devices.

[0201] Among them, the security authentication device 800 includes: a processor 802, a communication interface 803, and a memory 801. Optionally, the security authentication device 800 may further include a communication line 804. Among them, the communication interface 803, the processor 802, and the memory 801 can be interconnected through the communication line 804; the communication line 804 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The communication line 804 can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 8 only a thick line is used to represent it in the figure, but it does not mean that there is only one bus or one type of bus.

[0202] The processor 802 can be a CPU, a microprocessor, an ASIC, or one or more integrated circuits for controlling the execution of the program of the present application solution.

[0203] The communication interface 803 uses any device of the transceiver type for communicating with other devices or communication networks, such as Ethernet, radio access network (RAN), wireless local area networks (WLAN), wired access networks, etc.

[0204] The memory 801 can be a ROM or other type of static storage device that can store static information and instructions, a RAM or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory can exist independently and be connected to the processor through the communication line 804. The memory can also be integrated with the processor.

[0205] Among them, the memory 801 is used to store computer-executable instructions for implementing the solution of this application, and is controlled by the processor 802 to execute. The processor 802 is used to execute the computer-executable instructions stored in the memory 801, so as to implement the security authentication method provided in the above embodiments of this application.

[0206] Optionally, the computer-executable instructions in the embodiments of this application may also be referred to as application code, and the embodiments of this application do not make specific limitations on this.

[0207] Those of ordinary skill in the art can understand that: The various digital numbers such as the first and second involved in this application are only for the convenience of description and are not used to limit the scope of the embodiments of this application, nor do they represent the order. "And / or" describes the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after. "At least one" means one or more. At least two means two or more. "At least one", "any one" or their similar expressions refer to any combination of these items, including any combination of single item (s) or plural item (s). For example, at least one (piece, type) of a, b, or c can represent: a, b, c, a-b, a-c, b-c, or a-b-c, where a, b, c can be single or multiple. "Multiple" means two or more, and other quantifiers are similar. In addition, for elements where the singular forms "a", "an", and "the" appear, unless otherwise clearly specified in the context, they do not mean "one or only one", but mean "one or more than one". For example, "a device" means one or more such devices.

[0208] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wire (such as coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)), etc.

[0209] In the embodiments of the present application, the various illustrative logical units and circuits described can be implemented or operate the described functions through a design of a general-purpose processor, a digital signal processor, an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic, discrete hardware components, or any combination of the above. The general-purpose processor can be a microprocessor. Optionally, the general-purpose processor can also be any conventional processor, controller, microcontroller, or state machine. The processor can also be implemented by a combination of computing devices, such as a digital signal processor and a microprocessor, multiple microprocessors, one or more microprocessors combined with a digital signal processor core, or any other similar configuration.

[0210] The steps of the methods or algorithms described in the embodiments of the present application can be directly embedded in hardware, software units executed by a processor, or a combination of the two. The software units can be stored in a RAM memory, a flash memory, a ROM memory, an EPROM memory, an EEPROM memory, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium in the art. Exemplarily, the storage medium can be connected to the processor so that the processor can read information from the storage medium and write information to the storage medium. Optionally, the storage medium can also be integrated into the processor. The processor and the storage medium can be provided in an ASIC.

[0211] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are performed on the computer or other programmable apparatus to produce a computer-implemented process, thereby the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one process or multiple processes in the flowchart and / or one block or multiple blocks in the block diagram.

[0212] Although the present application has been described in conjunction with specific features and their embodiments, it is obvious that various modifications and combinations can be made thereto without departing from the scope of the present application. Accordingly, the present specification and the drawings are merely exemplary descriptions of the present application defined by the appended claims, and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of the present application. Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these changes and modifications.

Claims

1. A security authentication system, characterized in that, Including: An edge device, configured to determine at least one application software to be authenticated according to a first startup sequence, obtain authentication credential data from a connected secure storage device, and send the authentication credential data to a management service platform. The authentication credential data includes a second authentication credential and first authentication credentials respectively corresponding to the at least one application software. The first authentication credential corresponding to the first application software is generated based on a file of the first application software, where the first application software is any one of the at least one application software, and the second authentication credential is related to the identity identifier of the edge device; A secure storage device, configured to receive and store the first authentication credentials of the at least one application software and the second authentication credential sent by the edge device according to the first startup sequence; After receiving a credential reading instruction sent by the edge device, send the authentication credential data to the edge device. The management service platform is connected to the edge device, configured to receive the authentication credential data sent by the edge device and send an authentication result to the edge device; Wherein, the authentication result is used to indicate whether the edge device is a secure device; When none of the at least one application software is tampered with and the edge device is legitimate, the edge device is a secure device; otherwise, the edge device is an insecure device. When the first authentication credential of the first application software is the same as the first standard credential of the first application software stored in the management service platform, it indicates that the first application software is not tampered with. When the second authentication credential is the same as the second standard credential of the edge device stored in the management service platform, it indicates that the edge device is legitimate.

2. The system according to claim 1, characterized in that, The secure storage device is specifically configured to: Encrypt the received second authentication credential and the first authentication credentials corresponding to the at least one application software and then store them.

3. The system according to claim 2, characterized in that, The second authentication credential and the first authentication credentials respectively corresponding to the at least one application software included in the authentication credential data are encrypted by the secure storage device.

4. The system according to claim 3, wherein The management service platform is further configured to decrypt the second authentication credential and the first authentication credentials respectively corresponding to the at least one application software from the authentication credential data.

5. The system according to any one of claims 1 to 4, characterized in that, The at least one application software includes at least one of operating system layer software, container layer software, or application layer software.

6. The system according to claim 1, wherein The first authentication credential corresponding to the first application software is an encrypted value obtained by encrypting an image file of the first application software.

7. The system according to claim 1, wherein The edge device and the secure storage device are connected by any one of the following connection methods: Universal Serial Bus (USB) connection, Near Field Communication (NFC) connection, Ethernet connection, and serial port connection.

8. A security authentication method, characterized in that, Applied to an edge device, the method includes: Determine at least one application software to be authenticated according to a first startup sequence; Send a credential reading instruction to the connected secure storage device and obtain authentication credential data from the secure storage device; the authentication credential data includes a second authentication credential and first authentication credentials corresponding to at least one application software respectively. The first authentication credential corresponding to the first application software is generated based on the file of the first application software, and the first application software is any one of the at least one application software. The second authentication credential is related to the identity identifier of the edge device. Send the authentication credential data to the management service platform. Receive the authentication result sent by the management service platform. Wherein, the authentication result is used to indicate whether the edge device is a secure device. When none of the at least one application software is tampered with and the edge device is legal, the edge device is a secure device; otherwise, the edge device is an insecure device. When the first authentication credential of the first application software is the same as the first standard credential of the first application software stored in the management service platform, it indicates that the first application software is not tampered with. When the second authentication credential is the same as the second standard credential of the edge device stored in the management service platform, it indicates that the edge device is legal. Before sending the credential reading instruction to the connected secure storage device, it further includes: Store the first authentication credentials of the at least one application software and the second authentication credential in the secure storage device according to the first startup sequence.

9. The method according to claim 8, wherein The second authentication credential and the first authentication credentials corresponding to at least one application software included in the authentication credential data are encrypted by the secure storage device.

10. The method according to claim 8, wherein, The edge device is connected to the secure storage device by any one of the following connection methods: Universal Serial Bus (USB) connection, Near Field Communication (NFC) connection, Ethernet connection, and serial port connection.

11. The method according to claim 8 or 9, characterized in that, The at least one application software includes at least one of operating system layer software, container layer software, or application layer software.

12. The method according to claim 8, wherein The first authentication credential corresponding to the first application software is the encrypted value after encrypting the image file of the first application software.

13. A security authentication method, characterized in that, Applied to the management service platform, the method includes: Receive the authentication credential data sent by the edge device according to the first startup sequence. The authentication credential data is obtained by the edge device from the connected secure storage device. The authentication credential data includes a second authentication credential and first authentication credentials corresponding to at least one application software respectively. The first authentication credential corresponding to the first application software is generated based on the file of the first application software, and the first application software is any one of the at least one application software. The second authentication credential is related to the identity identifier of the edge device. Send the authentication result to the edge device. Wherein, the authentication result is used to indicate whether the edge device is a secure device. When none of the at least one application software is tampered with and the edge device is legal, the edge device is a secure device; otherwise, the edge device is an insecure device; when the first authentication credential of the first application software is the same as the first standard credential of the first application software stored in the management service platform, it indicates that the first application software is not tampered with; when the second authentication credential is the same as the second standard credential of the edge device stored in the management service platform, it indicates that the edge device is legal.

14. The method according to claim 13, wherein Before sending the authentication result to the edge device, the method further includes: Decrypting the second authentication credential and the first authentication credentials corresponding to the at least one application software respectively from the authentication credential data.

15. The method according to claim 13 or 14, characterized in that, The at least one application software includes at least one of operating system layer software, container layer software, or application layer software.

16. The method according to claim 13, wherein The first authentication credential corresponding to the first application software is the encrypted value obtained by encrypting the image file of the first application software.

17. A secure storage device, characterized in that, The secure storage device supports connection with the edge device, including: A communication module, configured to receive, after the edge device starts the authentication process, the first authentication credentials corresponding to at least one application software to be authenticated in a first startup order, where the first authentication credential corresponding to the first application software is generated based on the file of the first application software, and the first application software is any one of the at least one application software; A storage module, configured to store the second authentication credential of the edge device and store the first authentication credentials corresponding to the at least one application software received, where the second authentication credential is related to the identity identifier of the edge device; The communication module is further configured to, when receiving the credential reading instruction of the edge device, send the authentication credential data to the edge device in the first startup order, where the authentication credential data includes the second authentication credential and the first authentication credentials corresponding to the at least one application software respectively.

18. The device according to claim 17, characterized in that, The device further includes: An encryption module, configured to encrypt the received second authentication credential and the first authentication credentials corresponding to the at least one application software to obtain the authentication credential data.

19. An edge device, characterized in that, Including a processor and a memory, the memory stores program instructions, and the processor executes the program instructions to execute the method according to any one of claims 8 to 12.

20. A management service platform, characterized in that, Including a processor and a memory, the memory stores program instructions, and the processor executes the program instructions to execute the method according to any one of claims 13 to 16.

21. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store a computer program, and when the computer program runs on a computing device, the computing device is caused to execute the method according to any one of claims 8 - 16.

Citation Information

Patent Citations

  • Safe starting system and method, terminal equipment and core system thereof

    CN110532777A

  • Network security protection method, system and device, security switch and storage medium

    CN114374508A