A method for communicating between a host and a peripheral device

By realizing bidirectional data transmission between the host and peripheral devices in a system function call, the performance problems caused by the frequent communications in the prior art are solved, and more efficient data processing and secure transmission are achieved.

CN116893994BActive Publication Date: 2025-05-23INFORMATION SCI RES INST OF CETC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310641776.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-01
Publication Date
2025-05-23
Estimated Expiration
2043-06-01

AI Technical Summary

Technical Problem

In the prior art, communication between the host and the peripheral device requires multiple system function calls, resulting in large communication overhead and affecting the real-time data processing performance.

Method used

By making the host send and receive data at the same time in a system function call, the operation request instruction is used to include the operation operation type, data to be calculated and the data transmission direction. After receiving the instructions, the peripheral device performs analysis and calculation, and directly returns the result.

Benefits of technology

It reduces the number of interactions between the host and peripheral devices, reduces system communication overhead, and improves data processing performance and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116893994B_ABST
    Figure CN116893994B_ABST
Patent Text Reader

Abstract

The disclosed embodiment relates to the technical field of host and peripheral device communication, and provides a host and peripheral device communication method, including: the host sends a calculation request instruction to the peripheral device, the calculation request instruction includes a calculation operation type, data to be calculated, and a data transmission direction, wherein the data transmission direction is used to instruct the peripheral device to return the calculation result corresponding to the calculation request instruction to the host; the peripheral device receives the calculation request instruction, parses the calculation request instruction, extracts the data to be calculated, performs a calculation operation on the data to be calculated according to the calculation operation type, obtains the calculation result, and returns the calculation result to the host based on the data transmission direction. The disclosed embodiment reduces the number of interactions between the host and the peripheral device, thereby reducing the system communication overhead and improving the data processing capability and performance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of communication between a host and a peripheral device, and in particular to a communication method between a host and a peripheral device. Background Art

[0002] In the prior art, the host and peripheral devices need to make system calls when communicating. Generally, a request for a calculation operation requires two system function calls: the first call corresponds to the calculation request, and the second call is for the result request. The system function defines that a single call does not support bidirectional data transmission, that is, data is sent from the host to the peripheral device, and after the peripheral device completes the calculation, the calculation result is sent from the peripheral device to the host.

[0003] However, the above-mentioned communication method in the prior art will result in a large number of communications between the host and the peripheral device, causing communication overhead and affecting the real-time data processing performance. Therefore, if the host can send and receive data at the same time during a system function call, it will play a positive role in improving the data processing performance. However, the kernel of the existing operating system limits the interaction process between the host and the peripheral device. If you want to change the existing interaction process and optimize two system function calls to one system function call, you need to modify the kernel. If you modify the kernel, the versatility of the operating system will be reduced, and the heterogeneity of different host terminals and the compatibility of different operating systems will increase the cost of modifying the kernel. Therefore, how to find a method to realize a certain operation through a function call when the host calls the peripheral device without changing the kernel of the operating system is a considerable challenge. Summary of the invention

[0004] The present disclosure aims to solve at least one of the problems existing in the prior art and provides a communication method between a host and a peripheral device.

[0005] In one aspect of the present disclosure, a method for communication between a host and a peripheral device is provided, the method comprising:

[0006] The host sends a calculation request instruction to the peripheral device, wherein the calculation request instruction includes a calculation operation type, data to be calculated, and a data transmission direction, wherein the data transmission direction is used to instruct the peripheral device to return a calculation result corresponding to the calculation request instruction to the host;

[0007] The peripheral device receives the operation request instruction, parses the operation request instruction, extracts the data to be operated, performs an operation on the data to be operated according to the operation type, obtains the operation result, and returns the operation result to the host based on the data transmission direction.

[0008] Optionally, the peripheral device comprises a hardware security module.

[0009] Optionally, before the host sends a calculation request instruction to the peripheral device, the method further includes:

[0010] The user end composed of the host and the peripheral device negotiates a key with the server end;

[0011] If the key negotiation is successful, the host sends a key generation instruction to the peripheral device, wherein the key generation instruction carries session key derivation related parameters involved in the key negotiation;

[0012] The peripheral device and the server derive relevant parameters according to the preset long-term shared key and the session key to derive the session key.

[0013] Optionally, after the peripheral device and the server derive relevant parameters according to the preset long-term shared key and the session key respectively and derive the session key, the method further includes:

[0014] The host sends a cryptographic operation instruction to the peripheral device, where the cryptographic operation instruction carries a cryptographic operation request, a transmission direction, first original data, and at least one initial vector fragment, wherein the transmission direction is used to instruct the peripheral device to return first encrypted data corresponding to the first original data to the host;

[0015] The peripheral device receives the cryptographic operation instruction, extracts all the initial vector slices from the cryptographic operation instruction, synthesizes the extracted initial vector slices into an initial vector, and extends the initial vector according to the length of the first original data to obtain an extended initial vector;

[0016] The peripheral device encrypts the first original data using the extended initialization vector and the session key based on the counter mode to obtain the first encrypted data, and sends the first encrypted data to the host based on the transmission direction;

[0017] The host sends the first encrypted data to the server;

[0018] The server decrypts the first encrypted data using the extended initialization vector and the session key based on the counter mode.

[0019] Optionally, the cryptographic operation instruction includes a cryptographic operation SCSI instruction, and the transmission direction and the initial vector slice are both included in a command block packet of the cryptographic operation SCSI instruction.

[0020] Optionally, when the data volume of the first original data does not exceed a preset threshold, the command block packet of the cryptographic operation SCSI instruction further includes at least one data slice corresponding to the first original data.

[0021] Optionally, after the peripheral device and the server derive relevant parameters according to the preset long-term shared key and the session key respectively and derive the session key, the method further includes:

[0022] The server encrypts the second original data using the session key based on the counter mode to obtain second encrypted data;

[0023] The server sends the second encrypted data to the host;

[0024] The host sends the second encrypted data to the peripheral device;

[0025] Based on the counter mode, the peripheral device uses the session key to decrypt the second encrypted data to obtain the second original data, and sends the second original data to the host.

[0026] Optionally, the user end consisting of the host and the peripheral device performs key negotiation with the server end, including:

[0027] The host initiates a session application, and sends a session application instruction corresponding to the session application to the peripheral device;

[0028] The peripheral device receives the session application instruction and generates a random number R 1 , the random number R 1 Sending to the host;

[0029] The host sends the random number R 1 Sending to the server;

[0030] The server generates a random number R 2 , the random number R 2 Sent to the host, according to the random number R 1 , the random number R 2 and the preset long-term shared key to generate a first session key sk_s;

[0031] The host sends the session key generation instruction and the random number R 2 sending to the peripheral device;

[0032] The peripheral device generates an instruction based on the session key according to the random number R 1 , the random number R 2and the preset long-term shared key to generate a second session key sk_c, calculate a hash value hash(sk_c) of the second session key sk_c, and send hash(sk_c) to the host;

[0033] The host sends hash(sk_c) to the server;

[0034] The server calculates a hash value hash(sk_s) of the first session key sk_s, compares hash(sk_s) with hash(sk_c), and if hash(sk_s) is consistent with hash(sk_c), sends hash(sk_s) to the host;

[0035] The host verifies hash(sk_s) and hash(sk_c). If the verification result is that hash(sk_s) and hash(sk_c) are consistent, it means that the key negotiation is successful.

[0036] Optionally, the session key generation instruction includes a session key generation SCSI instruction, and the random number R 2 Included in the command block packet of the session key generation SCSI instruction.

[0037] Optionally, the operation code of the session key generation SCSI instruction is set to a manufacturer reserved value.

[0038] Compared with the prior art, the embodiments of the present disclosure have the following beneficial effects:

[0039] 1. In terms of performance, the communication process between the host and peripheral devices has been optimized, the system communication overhead has been reduced, and the overall system data processing capability has been improved.

[0040] 2. In terms of security, it can be applied to the transmission of special data such as sensitive data. The key can be stored in the non-volatile memory of the hardware security module in the peripheral device, which not only increases the security of the user-side key, ensures the security of the transmitted data, but also improves the communication performance.

[0041] 3. It is universal and suitable for communication between hosts and peripheral devices based on different protocols. It only requires expansion and modification of the communication protocol on the peripheral devices without modifying the host operating system kernel. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] One or more embodiments are exemplarily described by pictures in the corresponding drawings, and these exemplifications do not constitute limitations on the embodiments. Elements with the same reference numerals in the drawings represent similar elements, and unless otherwise stated, the figures in the drawings do not constitute proportional limitations.

[0043] Figure 1 A flow chart of interaction between a host and a peripheral device in the prior art;

[0044] Figure 2 A flow chart of a method for communication between a host and a peripheral device provided in one embodiment of the present disclosure;

[0045] Figure 3 A schematic diagram of the connection relationship between a host and a peripheral device provided in another embodiment of the present disclosure;

[0046] Figure 4 A flowchart of a method for communication between a host and a peripheral device provided in another embodiment of the present disclosure;

[0047] Figure 5 A flowchart of a method for communication between a host and a peripheral device provided in another embodiment of the present disclosure;

[0048] Figure 6 A schematic diagram of the encryption and decryption process in CTR mode provided by another embodiment of the present disclosure;

[0049] Figure 7 A flowchart of a method for communication between a host and a peripheral device provided in another embodiment of the present disclosure;

[0050] Figure 8 A schematic diagram of the structure of a cryptographic operation SCSI instruction provided by another embodiment of the present disclosure;

[0051] Fig. 9 A flowchart of a method for communication between a host and a peripheral device provided in another embodiment of the present disclosure;

[0052] Fig.10 A flowchart of a key negotiation process provided for another embodiment of the present disclosure;

[0053] Fig.11 A schematic diagram of the structure of a session key generating SCSI instruction provided by another embodiment of the present disclosure;

[0054] Fig.12 A timing diagram of a communication method between a host and a peripheral device provided in another embodiment of the present disclosure;

[0055] Fig.13 A flowchart of encryption operations between a host and a USB HSM provided in accordance with another embodiment of the present disclosure. DETAILED DESCRIPTION

[0056] In the prior art, the communication between the host and the peripheral device requires calling the system function. For example, the Unix system calls the ioctl() function, and the Windows system calls the DeviceIoControl() function. When the system function is called, an instruction code (request code) needs to be passed in, and the instruction code corresponds to the relevant function. The user program sends the instruction code to the kernel layer of the operating system, and then the kernel driver interprets the command according to the instruction code and performs the corresponding operation.

[0057] In the prior art, when a host communicates with a peripheral device, the host needs to pass the instruction code into the system function to be called, such as ioctl(), DeviceIoControl(), etc. Figure 1 , the communication process between the host and the peripheral device to realize the operation by calling the system function usually includes the following steps: 1. The host sends instructions based on the operation request, that is, the host sends the instruction code to the peripheral device to request the operation; 2. Data transmission from the host to the peripheral device, that is, the host sends the data to be calculated to the peripheral device; 3. The host sends instructions based on the request result, that is, the host sends the instruction code to the peripheral device to request the operation result corresponding to the operation request in the first step; 4. Data transmission from the peripheral device to the host, that is, the peripheral device sends the processed data to be calculated to the host. In the above communication process, the instruction code indicates the direction of data transmission, and data transmission can only be one-way, such as from the host to the peripheral device or from the device to the host. Therefore, if the host calls the peripheral device to implement a data operation process, it is necessary to call the system function function such as ioctl(), DeviceIoControl(), etc. twice. Each time the system function function is called, the host and the peripheral device need to interact twice. Among them, when the system function function is called for the first time, the host and the peripheral device communicate through Figure 1 Steps 1 and 2 in the above code complete two interactions. When the system function is called for the second time, the host and the peripheral device interact with each other through Figure 1 Steps 3 and 4 in the above code complete two interactions.

[0058] In order to make the purpose, technical scheme and advantages of the embodiments of the present disclosure clearer, the embodiments of the present disclosure will be described in detail below in conjunction with the accompanying drawings. However, it can be understood by those skilled in the art that in each embodiment of the present disclosure, many technical details are proposed in order to enable readers to better understand the present disclosure. However, even without these technical details and various changes and modifications based on the following embodiments, the technical scheme claimed for protection in the present disclosure can also be implemented. The division of the following embodiments is for the convenience of description and should not constitute any limitation on the specific implementation of the present disclosure. The various embodiments can be combined and referenced with each other without contradiction.

[0059] An embodiment of the present disclosure relates to a communication method between a host and a peripheral device. The method can reduce the performance consumption caused by the interaction process by reducing the number of interactions between the host and the peripheral device, thereby improving data processing capabilities.

[0060] like Figure 1 As shown, the host and peripheral device communication method provided in this embodiment includes the following steps:

[0061] In step S110, the host sends a calculation request instruction to the peripheral device, where the calculation request instruction includes a calculation operation type, data to be calculated, and a data transmission direction, wherein the data transmission direction is used to instruct the peripheral device to return a calculation result corresponding to the calculation request instruction to the host.

[0062] In step S120, the peripheral device receives the operation request instruction, parses the operation request instruction, extracts the data to be operated, performs an operation on the data to be operated according to the operation type, obtains the operation result, and returns the operation result to the host based on the data transmission direction.

[0063] Specifically, Figure 3 As shown in the figure, the peripheral device and the host can be connected through a data cable or through a host hardware interface (that is, the peripheral device is directly inserted into the host hardware interface). The communication between the host and the peripheral device can be realized based on the SCSI protocol. Among them, SCSI is the English abbreviation of Small Computer System Interface. The SCSI protocol is an independent processor standard for the system-level interface between the host and its peripheral devices (such as hard disks, floppy drives, optical drives, printers, scanners, etc.).

[0064] The host can be a computer, a restricted terminal or other device. The peripheral device can be capable of performing certain special operations such as data encryption, decryption, digital signature, etc. Exemplarily, the peripheral device can be a hardware security module (HSM), which provides the host with functions such as key generation and storage, data encryption and decryption operations, etc. Due to physical isolation and interface limitations, the hardware security module can provide better security performance for the key. For example, the peripheral device can be a Universal Serial Bus (USB) HSM. The USB HSM is a USB-based hardware security module that uses the SCSI protocol to communicate with the host and can be directly inserted into the USB hardware interface of the host to achieve communication connection with the host.

[0065] like Figure 4 As shown, the host and peripheral device communication method provided in this embodiment is Figure 1The communication process between the host and the peripheral device shown in the figure is simplified by calling the system function function to realize the operation. After simplification, the communication process of calling the system function function such as ioctl(), DeviceIoControl(), etc. to realize the operation includes the following two steps: Step 1, the host sends the instruction containing the operation request and the data to be calculated to the peripheral device at the same time, and indicates in the instruction that the peripheral device needs to return the data after the operation to the host. The peripheral device receives the instruction and the data to be calculated sent by the host, and completes the operation of the data to be calculated according to the instruction. Step 2, the peripheral device transmits the data obtained from the operation to the host. It can be seen that Figure 4 The communication process to achieve the operation will Figure 1 The four steps shown are optimized into two steps, reducing the number of interactions between the host and the peripheral device, thereby reducing communication overhead and improving performance.

[0066] Compared with the prior art, in the disclosed embodiment, the host sends the data to be calculated and the calculation operation type as components of the calculation request instruction to the peripheral device, and specifies in the calculation request instruction the data transmission direction for instructing the peripheral device to return the calculation result corresponding to the calculation request instruction to the host, so that after receiving the calculation request instruction, the peripheral device can directly return the calculation result obtained by performing the calculation operation on the data to be calculated according to the calculation operation type to the host, thereby reducing the number of interactions between the host and the peripheral device, thereby reducing the system communication overhead and improving the data processing capability and performance.

[0067] Exemplarily, before the user end consisting of the host and the peripheral device transmits data with the server end, it is necessary to perform key negotiation, and after the key negotiation is completed, a session key is generated, so that the session key can be used for data transmission later.

[0068] In step S110, before the host sends a computing request instruction to the peripheral device, Figure 5 The host and peripheral device communication method also includes a key negotiation process, which specifically includes the following steps:

[0069] In step S130, the user end consisting of the host and the peripheral device performs key negotiation with the server end. That is, the host of the user end starts to communicate with the server end, negotiates with the server end the parameters required to derive the session key, i.e., the session key derivation related parameters and other information, to achieve key negotiation. The host of the user end can communicate with the server end through the Internet based on existing security protocols such as the Secure Socket Layer (SSL) protocol and the Transport Layer Security (TLS) protocol.

[0070] Step S140: If the key negotiation is successful, the host sends a key generation instruction to the peripheral device, and the key generation instruction carries session key derivation related parameters involved in the key negotiation.

[0071] In step S150, the peripheral device and the server derive relevant parameters according to the preset long-term shared key and the session key to derive the session key. The peripheral device and the server may also periodically negotiate and update the session key to improve security.

[0072] Specifically, the preset long-term shared key can be a long-term shared key allocated by the user and the server, which is used to generate a session key between the two. The user can store the long-term shared key in a peripheral device, and the server can store the long-term shared key in its own security hardware module.

[0073] By setting up a key negotiation process, this embodiment can make the host and peripheral device communication method provided by this embodiment suitable for the transmission of special data such as sensitive data, which not only increases the security of the user-side session key, ensures the security of the transmitted data, but also improves the communication performance.

[0074] Exemplarily, after the key negotiation process, the host and peripheral device communication method further includes a data encryption / decryption process, and the encryption operation and the decryption operation can be implemented by the peripheral device or the server. The encryption process can be implemented using a counter mode (CounTeR, CTR) packet encryption function. Figure 6 As shown, when the CTR mode is used for encryption, the peripheral device or server first generates a key stream for encryption, and performs an XOR operation on the key stream and the data to be encrypted, namely, each plaintext block including plaintext block 0, plaintext block 1, plaintext block 2, ..., plaintext block N-1 to complete the data encryption, and obtain the corresponding ciphertext blocks, namely ciphertext block 0, ciphertext block 1, ciphertext block 2, ..., ciphertext block N-1. The generation of the key stream does not depend on the plaintext, namely, the data to be encrypted, but is only related to the counting initialization vector (IV) and the session key used for encryption. That is, in the CTR mode, each group corresponds to a counter (Counter) that is accumulated time by time, and the key stream is generated by encrypting the Counter using the session key. In other words, in the CTR mode, Figure 6As shown, the initial values ​​of Counter corresponding to the 1st to Nth groups are expressed as IV, IV+1, IV+2, ..., IV+N-1 respectively. IV, IV+1, IV+2, ..., IV+N-1 form an IV stream, and the IV stream is encrypted using the session key to obtain the corresponding key stream. Correspondingly, when decrypting in CTR mode, the initial values ​​of Counter IV, IV+1, IV+2, ..., IV+N-1 corresponding to the 1st to Nth groups form an IV stream, and the IV stream is encrypted using the session key to obtain the corresponding key stream. The key stream is used to decrypt each ciphertext block, i.e., ciphertext block 0, ciphertext block 1, ciphertext block 2, ..., ciphertext block N-1, to obtain the corresponding plaintext blocks, i.e., plaintext block 0, plaintext block 1, plaintext block 2, ..., plaintext block N-1.

[0075] Exemplarily, after step S150, Figure 7 The host and peripheral device communication method also includes a process in which the peripheral device is used for encryption and the server is used for decryption, which specifically includes the following steps:

[0076] In step S710, the host sends a cryptographic operation instruction to the peripheral device, where the cryptographic operation instruction carries a cryptographic operation request, a transmission direction, first original data, and at least one initial vector fragment, wherein the transmission direction is used to instruct the peripheral device to return first encrypted data corresponding to the first original data to the host.

[0077] Step S720: The peripheral device receives the cryptographic operation instruction, extracts all initial vector fragments from the cryptographic operation instruction, synthesizes the extracted initial vector fragments into an initial vector, and expands the initial vector according to the length of the first original data to obtain an expanded initial vector.

[0078] In step S730, the peripheral device encrypts the first original data using the extended initial vector and the session key based on the counter mode to obtain first encrypted data, and sends the first encrypted data to the host based on the transmission direction.

[0079] In step S740, the host sends the first encrypted data to the server.

[0080] Step S750: The server decrypts the first encrypted data using the extended initialization vector and the session key based on the counter mode.

[0081] For example, in CTR encryption mode, the initial vector sharding can be obtained by sharding the extended initial vector, i.e., the IV stream, so that the host can transmit the extended initial vector, i.e., the IV stream, as plaintext data to the peripheral device, so that the peripheral device directly uses the session key to encrypt the extended initial vector to obtain the key stream. Alternatively, in CTR encryption mode, the initial vector sharding can also be obtained by sharding the initial value IV of the Counter corresponding to the first group in the CTR mode, so that the host can transmit the initial value IV of the Counter corresponding to the first group to the peripheral device, and the peripheral device generates the corresponding IV stream, i.e., the extended initial vector, based on the initial value IV, and on this basis, encrypts the extended initial vector using the session key to obtain the key stream.

[0082] This embodiment can halve the encryption system call overhead between the host and the peripheral device by setting the cryptographic operation instruction sent by the host to the peripheral device to carry a cryptographic operation request, a transmission direction, the first original data and at least one initial vector fragment, further reducing the number of interactions between the host and the peripheral device during the data encryption process, reducing system communication overhead, improving encryption throughput, and improving data processing capabilities and performance.

[0083] Exemplarily, the cryptographic operation instruction includes a cryptographic operation SCSI instruction, and the transmission direction and the initial vector slice are both included in a command block wrapper (CBW) of the cryptographic operation SCSI instruction.

[0084] Specifically, in the cryptographic operation SCSI instruction, the 13th byte of the CBW data block indicates the transmission direction, and CBW[8-11], i.e., the 8th to 11th bytes of the CBW data block, indicates the length of the data to be transmitted. In fact, the SCSI command in the CBW implies the direction and length of the data to be transmitted, because the SCSI specification has clearly defined the data format corresponding to this command. The length of the initial vector IV in the CTR mode is 16 bytes, so the initial vector IV can be split and placed in the reserved field or unused field of the CBW. When the peripheral device receives the CBW, it can extract the split initial vector IV from the CBW, recombine and expand it, and use the expanded initial vector IV to complete data encryption. This can save the overhead of sending instructions once, thereby improving the encryption throughput.

[0085] like Figure 8 As shown, the 16-byte cryptographic operation SCSI instruction may include an operation code OP and a split initial vector IV, wherein the operation code OP may occupy one byte, namely byte 0, and the split initial vector IV, namely IV[0-14], may occupy 15 bytes, namely bytes 1-15.

[0086] Exemplarily, when the data volume of the first original data does not exceed a preset threshold value, such as 20 bytes, the command block packet of the cryptographic operation SCSI instruction also includes at least one data fragment corresponding to the first original data. That is, when the data volume of the first original data does not exceed a preset threshold value, such as not exceeding 20 bytes, the first original data can be fragmented, and the fragmented first original data is placed in the CBW of the cryptographic operation SCSI instruction.

[0087] Exemplarily, after step S150, Fig. 9 The host and peripheral device communication method also includes a process in which the server is used for encryption and the peripheral device is used for decryption, which specifically includes the following steps:

[0088] Step S910: The server encrypts the second original data using the session key based on the counter mode to obtain second encrypted data.

[0089] In step S920, the server sends the second encrypted data to the host.

[0090] Step S930: the host sends the second encrypted data to the peripheral device.

[0091] Step S940: The peripheral device decrypts the second encrypted data using the session key based on the counter mode to obtain the second original data, and sends the second original data to the host.

[0092] This implementation method can further enhance the data processing capability of the system by utilizing server-side encryption and peripheral equipment for decryption.

[0093] Exemplarily, during the key negotiation process, step S130 includes: the host initiates a session application, and sends a session application instruction corresponding to the session application to the peripheral device. The peripheral device receives the session application instruction, generates a random number R 1 , the random number R 1 The host sends the random number R 1 Sent to the server. The server generates a random number R 2 , the random number R 2 Sent to the host, according to the random number R 1 , random number R 2 The host generates the first session key sk_s with the preset long-term shared key. 2 The peripheral device generates instructions based on the session key and sends the random number R 1 , random number R 2The server generates the second session key sk_c with the preset long-term shared key, calculates the hash value hash(sk_c) of the second session key sk_c, and sends hash(sk_c) to the host. The host sends hash(sk_c) to the server. The server calculates the hash value hash(sk_s) of the first session key sk_s, compares hash(sk_s) with hash(sk_c), and if hash(sk_s) and hash(sk_c) are consistent, hash(sk_s) is sent to the host. The host verifies hash(sk_s) and hash(sk_c). If the verification result is that hash(sk_s) and hash(sk_c) are consistent, it means that this key negotiation is successful.

[0094] Specifically, the existing session key negotiation process can be divided into three stages according to the TLS protocol. This embodiment provides an optimized key negotiation method. Taking the peripheral device as a USB HSM as an example, Fig.10 The key negotiation process provided in this embodiment includes the following steps:

[0095] 1. The user host initiates a session request and sends a session request instruction to the USB HSM.

[0096] 2. USB HSM receives the session request instruction and generates a random number R 1 and transmit the random number R 1 Sent to the host, the host transmits the random number R 1 Sent to the server on the server side.

[0097] 3. The server generates a random number R 2 and transmit the random number R 2 The host sends the session key generation instruction and the random number R to the host. 2 Sent to USB HSM, the server generates a random number R 1 , random number R 2 and a preset long-term shared key to generate a first session key sk_s;

[0098] 4. USB HSM generates instructions based on the session key, according to the random number R 1 , random number R 2 and a preset long-term shared key to generate a second session key sk_c, calculate a hash value hash(sk_c) of the second session key sk_c, and send hash(sk_c) as data to the host, and the host sends hash(sk_c) to the server through data transmission;

[0099] 5. The server calculates the hash value hash(sk_s) of the first session key sk_s, and compares the two hash values, hash(sk_s) and hash(sk_c): If hash(sk_s) and hash(sk_c) are inconsistent, the key negotiation fails; if hash(sk_s) and hash(sk_c) are consistent, the server sends hash(sk_s) as data to the host. The host verifies the two hash values, hash(sk_s) and hash(sk_c): If the verification result is that hash(sk_s) and hash(sk_c) are consistent, it means that this key negotiation is successful; if the verification result is that hash(sk_s) and hash(sk_c) are inconsistent, it means that this key negotiation fails.

[0100] In the prior art, when performing key negotiation, the host and the peripheral device need to interact three times, one interaction includes command sending and data transmission, wherein the step of command sending is odd number, the step of data transmission is even number, and two SCSI commands need to be sent in one interaction. The key negotiation method provided in this embodiment can combine the two SCSI commands in the prior art into one, and only two interactions are required between the host and the peripheral device, which can theoretically save 33% of time overhead.

[0101] The key negotiation process of this implementation can reduce the key negotiation system call overhead by nearly one third, further reducing the system communication overhead and improving system performance.

[0102] Exemplarily, the session key generation instruction includes a session key generation SCSI instruction, a random number R 2 Contained in the command block packet of the Session Key Generation SCSI command.

[0103] Specifically, Fig.11 As shown, the session key generation SCSI instruction may include an OP code field, a 0 field, a random number R 2 field, command (Control) field, reserved (Reserved) field. Among them, the OP code field can occupy one byte, namely byte 0, the 0 field can occupy one byte, namely byte 1, and the random number R 2 The field can occupy 12 bytes, namely R 2 [0-8] field occupies bytes 2-10, R 2 The [9-11] field occupies bytes 9-11, the Control field may occupy one byte, namely byte 11, and the Reserved field may occupy one byte, namely byte 15.

[0104] For example, the OP code in the session key generation SCSI instruction is set to a manufacturer reserved value such as 0xC3. At this time, when the peripheral device receives the instruction code 0xC3 in the session key generation SCSI instruction, the peripheral device can take out the 12-byte random number R from the CBWCB (device execution command block) of the session key generation SCSI instruction. 2 , using the random number R 2 Generate a session key, put the hash value of the session key into the cache and finally output it to the host.

[0105] In order to enable those skilled in the art to better understand the above embodiments, Fig.12 Take this as an example to illustrate.

[0106] like Fig.12 As shown, the host and the peripheral device constitute the user end, and the server end is connected to the host through the Internet. A method for communication between the host and the peripheral device includes the following steps:

[0107] The user end and the server end allocate a long-term shared key. The user end stores the long-term shared key in the peripheral device, and the server end stores the key in the secure hardware module of the server end.

[0108] Key negotiation phase: 1. The user host starts communicating with the server to negotiate the key. During this process, the user host and the server can negotiate the information such as the parameters related to the session key. 2. The user host sends the key generation instruction to the user peripheral device. 3. The user peripheral device and the server derive the session key using the long-term shared key and related parameter information. The session key can be negotiated and updated regularly.

[0109] Data encryption and decryption stage:

[0110] Peripheral device encryption and server-side decryption process: 1-1. The user-side host sends the original data to be encrypted, such as real-time streaming data, to the user-side peripheral device; 1-2. The user-side peripheral device can use CTR mode encryption, encrypt the original data based on the initial vector IV using the negotiated session key, and send the encrypted data to the user-side host; 1-3. The user-side host sends the encrypted data to the server; 1-4. The server uses the session key to decrypt the real-time streaming data sent by the user.

[0111] Server-side encryption and peripheral device decryption process: 2-1. The server adopts CTR mode encryption, encrypts the data based on the initial vector IV using the negotiated session key, and sends the encrypted data to the user-side host; 2-2. The user-side host sends the encrypted data to the peripheral device; 2-3. The peripheral device decrypts the encrypted data using the session key, and the peripheral device sends the decrypted data to the host.

[0112] When the peripheral device is a USB HSM, Fig.13 , the encryption operation process between the host and the USB HSM includes the following steps:

[0113] 1. The host sends a command to the USB HSM, which carries a cryptographic operation request, the initial vector IV of the slice, and the data to be encrypted. At the same time, the command also indicates that the data transmission direction is from USB HSM to the host, instructing the USB HSM to transmit the encrypted data to the host.

[0114] 2. The USB HSM receives the command sent by the host, extracts the fragments of the initial vector IV from the command, combines the fragments into the initial vector IV, extends the IV according to the length of the data to be encrypted, encrypts the data to be encrypted using the extended IV, and transmits the encrypted ciphertext to the host.

[0115] Those skilled in the art will appreciate that the above-mentioned embodiments are specific embodiments for implementing the present disclosure, and in actual applications, various changes may be made thereto in form and detail without departing from the spirit and scope of the present disclosure.

Claims

1. A method for communication between a host and a peripheral device, It is characterized in that The method comprises: The host sends a calculation request instruction to the peripheral device, wherein the calculation request instruction includes a calculation operation type, data to be calculated, and a data transmission direction, wherein the data transmission direction is used to instruct the peripheral device to return a calculation result corresponding to the calculation request instruction to the host; The peripheral device receives the operation request instruction, parses the operation request instruction, extracts the data to be operated, performs an operation on the data to be operated according to the operation type, obtains the operation result, and returns the operation result to the host based on the data transmission direction; Before the host sends a calculation request instruction to the peripheral device, the method further includes: The user end composed of the host and the peripheral device negotiates a key with the server end; If the key negotiation is successful, the host sends a key generation instruction to the peripheral device, wherein the key generation instruction carries session key derivation related parameters involved in the key negotiation; The peripheral device and the server derive relevant parameters according to the preset long-term shared key and the session key to derive the session key; After the peripheral device and the server derive relevant parameters according to the preset long-term shared key and the session key respectively, and derive the session key, the method further includes: The host sends a cryptographic operation instruction to the peripheral device, where the cryptographic operation instruction carries a cryptographic operation request, a transmission direction, first original data, and at least one initial vector fragment, wherein the transmission direction is used to instruct the peripheral device to return first encrypted data corresponding to the first original data to the host; The peripheral device receives the cryptographic operation instruction, extracts all the initial vector slices from the cryptographic operation instruction, synthesizes the extracted initial vector slices into an initial vector, and extends the initial vector according to the length of the first original data to obtain an extended initial vector; The peripheral device encrypts the first original data using the extended initialization vector and the session key based on the counter mode to obtain the first encrypted data, and sends the first encrypted data to the host based on the transmission direction; The host sends the first encrypted data to the server; The server decrypts the first encrypted data using the extended initialization vector and the session key based on the counter mode.

2. The method according to claim 1, It is characterized in that The peripheral device includes a hardware security module.

3. The method according to claim 1, It is characterized in that The cryptographic operation instruction includes a cryptographic operation SCSI instruction, and the transmission direction and the initial vector slice are both included in the command block packet of the cryptographic operation SCSI instruction.

4. The method according to claim 3, It is characterized in that When the data volume of the first original data does not exceed a preset threshold, the command block packet of the cryptographic operation SCSI instruction further includes at least one data slice corresponding to the first original data.

5. The method according to claim 1, It is characterized in that After the peripheral device and the server derive relevant parameters according to the preset long-term shared key and the session key respectively, and derive the session key, the method further includes: The server encrypts the second original data using the session key based on the counter mode to obtain second encrypted data; The server sends the second encrypted data to the host; The host sends the second encrypted data to the peripheral device; Based on the counter mode, the peripheral device uses the session key to decrypt the second encrypted data to obtain the second original data, and sends the second original data to the host.

6. The method according to any one of claims 1 to 5, It is characterized in that The user end composed of the host and the peripheral device performs key negotiation with the server end, including: The host initiates a session application, and sends a session application instruction corresponding to the session application to the peripheral device; The peripheral device receives the session application instruction and generates a random number R 1 , the random number R 1 Sending to the host; The host sends the random number R 1 Sending to the server; The server generates a random number R 2 , the random number R 2 Sent to the host, according to the random number R 1 , the random number R 2 and the preset long-term shared key to generate a first session key sk_s; The host sends the session key generation instruction and the random number R 2 sending to the peripheral device; The peripheral device generates an instruction based on the session key according to the random number R 1 , the random number R 2 and the preset long-term shared key to generate a second session key sk_c, calculate a hash value hash(sk_c) of the second session key sk_c, and send hash(sk_c) to the host; The host sends hash(sk_c) to the server; The server calculates a hash value hash(sk_s) of the first session key sk_s, compares hash(sk_s) with hash(sk_c), and if hash(sk_s) is consistent with hash(sk_c), sends hash(sk_s) to the host; The host verifies hash(sk_s) and hash(sk_c). If the verification result is that hash(sk_s) and hash(sk_c) are consistent, it means that the key negotiation is successful.

7. The method according to claim 6, It is characterized in that The session key generation instruction includes a session key generation SCSI instruction, the random number R 2 Included in the command block packet of the session key generation SCSI instruction.

8. The method according to claim 7, It is characterized in that The operation code of the session key generation SCSI instruction is set to a manufacturer reserved value.

Citation Information

Patent Citations

  • USB information security equipment and method for communication between USB information security equipment and mainframe

    CN101706854A