A dual-end encryption authentication method for host bus adapter

By introducing a dual authentication mechanism of finger vein recognition and ARP protocol into the host bus adapter, the problem of insufficient security of the host bus adapter is solved, and high security and reliability of data transmission are achieved.

CN118487805BActive Publication Date: 2025-09-23HANGZHOU DIANZI UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410560906.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-05-08
Publication Date
2025-09-23
Estimated Expiration
2044-05-08

AI Technical Summary

Technical Problem

In the existing technology, the security of the host bus adapter is ignored, resulting in a high risk of data leakage in the data center. In addition, the existing fingerprint or face recognition methods are not reliable and are easily interfered by external factors.

Method used

Finger vein recognition technology is combined with the Address Resolution Protocol (ARP) to set up security authentication on the PCIe and SATA/SAS ports of the host bus adapter respectively. Dual authentication is performed through MAC address and finger vein recognition to ensure the security of the data transmission channel.

Benefits of technology

It improves the security of data transmission, reduces the probability of host bus adapter being stolen and misused, enhances user privacy protection, and ensures the reliability and security of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118487805B_ABST
    Figure CN118487805B_ABST
Patent Text Reader

Abstract

The present invention discloses a dual-end encryption authentication method for a host bus adapter. The present invention adopts physical address (MAC) authentication and finger vein recognition authentication to realize encryption protection of the host bus adapter. First, the main control chip obtains the MAC address of the target host through the wireless network communication module, and then realizes MAC address authentication, and performs finger vein recognition authentication after passing the authentication. After passing the dual-end authentication, the data transmission channels of the PCIe end and the SATA / SAS end are both opened, and the host can read and write the connected device normally through the host bus adapter. At the same time, the wireless network communication module can back up the parameters generated during the operation of the host bus adapter in real time. The present invention can solve the current problem of lack of security of the host bus adapter, greatly improve the security of the data center, ensure the security and stability of data transmission between the host and the device, and help researchers to analyze and debug when data transmission is abnormal.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of host bus adapter security, specifically to the fields of biosecurity and network communications. The method mainly uses finger vein recognition technology and Address Resolution Protocol (ARP) to establish a two-way security authentication mechanism to achieve dual control of host ports and device ports. Background Art

[0002] With the development of the internet, data centers have become an integral part of modern society. Industries like data analysis, artificial intelligence, and cloud computing all require massive amounts of data to operate. This leads to enormous data center storage requirements, and the market demand for large-capacity storage arrays is increasing. Host bus adapters (HBAs) can significantly expand storage capacity, playing a crucial role in the big data era.

[0003] However, most data centers currently rely on solid-state drive encryption to protect data security, while neglecting the security of host bus adapters, which can easily lead to data leakage on the host side. Currently, fingerprint and facial recognition, which are widely used, are susceptible to interference from external factors. Fingerprint recognition accuracy is easily affected by skin conditions, while facial recognition is easily affected by lighting and standing position, making it less reliable. Summary of the Invention

[0004] The present invention aims to address the shortcomings of the existing technology and proposes a dual-end encryption authentication method for a host bus adapter. The method sets security authentication for the PCIe port and SATA / SAS port of the host bus adapter respectively, significantly improving the security of data transmission.

[0005] The specific technical solutions of the present invention are as follows:

[0006] Step 1: Add a wireless network communication module, a finger vein recognition module and a buzzer to the host bus adapter; the main control chip of the host bus adapter is electrically connected to the wireless network communication module and the finger vein recognition module; the wireless network communication module and the finger vein recognition module are both electrically connected to the buzzer.

[0007] Step 2: First, after the host bus adapter is connected to the host through the PCIe interface and powered on, the main control chip activates the wireless network communication module, connecting it to the local area network. The wireless network communication module then obtains the physical address (MAC) of the target host through the Address Resolution Protocol (ARP). Finally, the main control chip compares the MAC address received by the wireless network communication module with the previously stored host MAC address. By determining whether the received MAC address matches the previously stored address, the main control chip controls whether the data transmission channel on the PCIe side is open.

[0008] Step 3: After the host bus adapter successfully authenticates the MAC address, it will perform finger vein recognition authentication. The main control chip controls whether the data transmission channel on the SATA / SAS side is open based on the result of finger vein recognition.

[0009] Step 4: Once the data transmission channels on both the PCIe and SATA / SAS sides are open, the host can read and write to the connected devices normally through the host bus adapter (HBA). The wireless network communication module will send the operating status of the HBA card to the host in real time and upload it to the designated cloud for backup.

[0010] As a preferred technical solution of the present invention, in step 2, the host bus adapter (HBA card) obtains the host's MAC address through the ARP protocol. After the HBA card obtains the host's MAC address, it stores this address in the local ARP cache for future communication. The specific steps are as follows:

[0011] Step 2-1. The HBA sends an ARP request broadcast to the local network. The request contains the IP address of the host that the HBA wants to communicate with.

[0012] Step 2-2. All hosts on the same network will receive this ARP request, but only the target host will respond;

[0013] Step 2-3. After receiving the ARP request, the target host sends its own MAC address to the wireless network communication module. The HBA card establishes communication with the host through the MAC address.

[0014] Step 2-4. The main control chip compares the MAC address received by the wireless communication module with its previously stored host MAC address. If the addresses match, data transmission on the PCIe interface is enabled. If the addresses do not match, a command is returned to the wireless communication module to retrieve the address. If authentication fails six times in a row, the wireless communication module sends an error alert to the host bus adapter's owner's communication device, silences the module for 10 minutes, and triggers a buzzer alarm. When the wireless communication module is unmuted, the alarm is cleared, and authentication is restarted from step 2.

[0015] As a preferred technical solution of the present invention, in step 3, the specific steps of finger vein recognition are as follows:

[0016] Step 3-1. Vein scanning: Place the user's fingertip on the sensor of the finger vein recognition module, and use infrared light or near-infrared light to capture the image of the finger vein;

[0017] Step 3-2. Image correction: Adjust the position and angle of the image to meet the specifications;

[0018] Step 3-3. Feature extraction: Based on the image obtained above, extract the vein distribution image and obtain a feature map;

[0019] Step 3-4. Image comparison and matching: Compare the feature map obtained above with the original template stored in the main control chip and calculate the correlation;

[0020] Steps 3-5. If finger vein recognition passes, the data transmission path on the SATA / SAS port is enabled. Otherwise, finger vein recognition will be repeated. If authentication fails six times in a row, the wireless network communication module will send an error alarm to the host bus adapter's owner's communication device, the finger vein recognition module will be silenced for 10 minutes, and a buzzer alarm will be triggered. Once the finger vein recognition module is unmuted, the alarm will be cleared, and authentication will be restarted from step 2.

[0021] A host bus adapter (HBA) capable of implementing dual-end encryption authentication comprises an HBA board, a wireless network communication module, a finger vein recognition module, and a buzzer. The HBA board includes a main control chip, a power chip, a PCIe interface, and a SATA / SAS interface. The main control chip is electrically connected to the wireless network communication module, the finger vein recognition module, the power chip, the PCIe interface, and the SATA / SAS interface, respectively. The wireless network communication module and the finger vein recognition module are both electrically connected to the buzzer.

[0022] Beneficial effects of the present invention:

[0023] 1. The present invention adopts a dual-end encryption authentication mechanism of MAC address identification and finger vein identification on the HBA card, which increases the security operation index of the data center, reduces the probability of HBA card theft and confusion, and enhances user privacy.

[0024] 2. This invention uses finger vein recognition for authentication. Finger vein recognition technology is highly secure and reliable due to its unique biometric characteristics and difficulty in duplication. Furthermore, finger vein recognition offers enhanced privacy protection. Because finger vein recognition technology leaves no traces or can be misused, it prevents users' personal information from being leaked or used for illegal purposes.

[0025] 3. The present invention ensures the security of data transmission between the hard disk and the host by performing double-end encryption authentication, preventing outsiders from using the data without permission, and also preventing the HBA card from being used outside the specific area.

[0026] 4. The present invention can transmit the relevant parameters generated by the HBA card during use to the host in real time through wireless communication and upload them to a designated cloud for backup. This is beneficial for researchers to conduct error analysis when problems arise. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] Figure 1 is the overall flow chart of the invention;

[0028] Figure 2 Schematic diagram of electrical connection of the present invention;

[0029] Figure 3 A flowchart of MAC address authentication between the host bus adapter and the host in step 1;

[0030] Figure 4 This is a flowchart of finger vein recognition in step 2. DETAILED DESCRIPTION

[0031] The technical solution of the present invention is further described below in conjunction with the accompanying drawings and embodiments.

[0032] The present invention provides a host bus adapter that can realize double-end encryption authentication, and its structure includes an HBA board body, a wireless network communication module, a finger vein recognition module, and a buzzer. The HBA board body includes a main control chip, a power chip, a PCIe interface, and a SATA / SAS interface; the main control chip is electrically connected to the wireless network communication module, the finger vein recognition module, the power chip, the PCIe interface, and the SATA / SAS interface respectively. The wireless network communication module and the finger vein recognition module are both electrically connected to the buzzer. Its electrical connection is as follows: Figure 2 shown.

[0033] The wireless network communication module is used to communicate with the host. After connecting to the local area network, it obtains the MAC address of the target host through the ARP protocol, and can send the relevant parameters generated by the HBA card during use to the host in real time and upload them to the designated cloud for backup.

[0034] The finger vein recognition module is used to identify and authenticate the user's finger veins. It completes the finger vein recognition work through four steps: vein scanning, image correction, feature extraction, and image comparison and matching.

[0035] like Figure 1 As shown, a double-end encryption authentication method using the aforementioned host bus adapter is as follows:

[0036] Step 1: Add a wireless network communication module, a finger vein recognition module, and a buzzer to a host bus adapter; electrically connect the host bus adapter's main control chip to the wireless network communication module and the finger vein recognition module; and electrically connect the wireless network communication module and the finger vein recognition module to the buzzer.

[0037] Step 2: First, after the host bus adapter is connected to the host through the PCIe interface and powered on, the main control chip activates the wireless network communication module, connecting it to the local area network. The wireless network communication module then obtains the physical address (MAC) of the target host through the Address Resolution Protocol (ARP). Finally, the main control chip compares the MAC address received by the wireless network communication module with the previously stored host MAC address. By determining whether the received MAC address matches the previously stored address, the main control chip controls whether the data transmission channel on the PCIe side is open.

[0038] The MAC address authentication process is as follows Figure 3 As shown, the details are as follows:

[0039] Step 2-1. The HBA sends an ARP request broadcast to the local network. The request contains the IP address of the host that the HBA wants to communicate with.

[0040] Step 2-2. All hosts on the same network will receive this ARP request, but only the target host will respond;

[0041] Step 2-3. After receiving the ARP request, the target host sends its own MAC address to the wireless network communication module. The HBA card establishes communication with the host through the MAC address.

[0042] Step 2-4. The main control chip compares the MAC address received by the wireless communication module with its previously stored host MAC address. If the addresses match, the PCIe data transmission path is opened. If the addresses do not match, a command is returned to the wireless communication module to re-acquire the address. If authentication fails six times in a row, the wireless communication module will send an error alarm to the communication device of the host bus adapter owner, the wireless communication module will be silent for 10 minutes, and a buzzer alarm will be triggered. When the wireless communication module is unsilenced, the alarm will be cleared, and authentication will resume from step 2.

[0043] Step 3: After the host bus adapter successfully authenticates the MAC address, it will perform finger vein recognition authentication. The main control chip controls whether the data transmission channel on the SATA / SAS side is open based on the result of finger vein recognition.

[0044] The process of finger vein recognition is as follows Figure 4 As shown, the details are as follows:

[0045] Step 3-1. Vein scanning: Place the user's fingertip on the sensor of the finger vein recognition module, and use infrared light or near-infrared light to capture the image of the finger vein;

[0046] Step 3-2. Image correction: Adjust the position and angle of the image to meet the specifications;

[0047] Step 3-3. Feature extraction: Based on the image obtained above, extract the vein distribution image and obtain a feature map;

[0048] Step 3-4. Image comparison and matching: Compare the feature map obtained above with the original template stored in the main control chip and calculate the correlation;

[0049] Steps 3-5. If finger vein recognition passes, the data transmission path to the SATA / SAS port is enabled. Otherwise, finger vein recognition is repeated. If authentication fails six times in a row, the wireless network communication module sends an error alarm to the host bus adapter's owner's communication device. The finger vein recognition module is silenced for 10 minutes, and a buzzer alarm is triggered. Once the finger vein recognition module is unmuted, the alarm is cleared, and authentication is restarted from step 2.

[0050] Step 4: Once the data transmission channels on both the PCIe and SATA / SAS sides are open, the host can read and write to the connected devices normally through the host bus adapter (HBA). The wireless network communication module will send the operating status of the HBA card to the host in real time and upload it to the designated cloud for backup.

[0051] The above description is a further detailed description of the present invention in conjunction with specific / preferred embodiments, and the specific implementation of the present invention should not be considered to be limited to these descriptions. Those skilled in the art of the present invention may make various substitutions or modifications to the described embodiments without departing from the scope of the present invention, and such substitutions or modifications should be considered to fall within the scope of protection of the present invention.

[0052] Parts of the present invention that are not described in detail belong to the common knowledge of those skilled in the art.

Claims

1. A double-end encryption authentication method for a host bus adapter, characterized in that: The steps are as follows: Step 1: Add a wireless network communication module, a finger vein recognition module, and a buzzer to a host bus adapter; electrically connect the host bus adapter's main control chip to the wireless network communication module and the finger vein recognition module; and electrically connect the wireless network communication module and the finger vein recognition module to the buzzer. Step 2: First, after the host bus adapter is connected to the host through the PCIe interface and powered on, the main control chip will activate the wireless network communication module to connect it to the local area network; The wireless network communication module then obtains the physical address (MAC) of the target host through the Address Resolution Protocol (ARP). Finally, the main control chip compares the MAC address received by the wireless network communication module with the previously stored host MAC address. By determining whether the received MAC address is consistent with the previously stored address, it controls whether the data transmission channel on the PCIe side is open. Step 3: After the host bus adapter successfully authenticates the MAC address, it will perform finger vein recognition authentication. The main control chip controls whether the data transmission channel on the SATA / SAS side is open based on the result of finger vein recognition. Step 4: Once the data transmission channels on both the PCIe and SATA / SAS sides are open, the host can read and write to the connected devices normally through the host bus adapter (HBA). The wireless network communication module will send the operating status of the HBA card to the host in real time and upload it to the designated cloud for backup.

2. The double-end encryption authentication method for a host bus adapter according to claim 1, wherein: In step 1, the host bus adapter obtains the host's MAC address through the ARP protocol. After the HBA card obtains the host's MAC address, it stores this address in the local ARP cache for future communication. The specific steps are as follows: Step 2-1. The HBA sends an ARP request broadcast to the local network. The request contains the IP address of the host that the HBA wants to communicate with. Step 2-2. All hosts on the same network will receive this ARP request, but only the target host will respond; Step 2-3. After receiving the ARP request, the target host sends its own MAC address to the wireless network communication module. The HBA card establishes communication with the host through the MAC address. Step 2-4. The main control chip compares the MAC address received by the wireless network communication module with its previously stored host MAC address; If the address matches completely, the data transmission path on the PCIe side is opened; If the address does not match, the instruction is returned to the wireless network communication module to re-acquire the address; If the authentication fails for 6 times in a row, the wireless network communication module will send an error alarm to the communication device of the host bus adapter owner, the wireless network communication module will be silent for 10 minutes, and the buzzer alarm will be triggered; When the wireless network communication module is released from silent state, the alarm is lifted and authentication will be restarted from step 2.

3. The double-end encryption authentication method for a host bus adapter according to claim 1, wherein: In step 3, the specific steps of finger vein recognition are as follows: Step 3-1. Vein scanning: Place the user's fingertip on the sensor of the finger vein recognition module, and use infrared light or near-infrared light to capture the image of the finger vein; Step 3-2. Image correction: Adjust the position and angle of the image to meet the specifications; Step 3-3. Feature extraction: Based on the image obtained above, extract the vein distribution image and obtain a feature map; Step 3-4. Image comparison and matching: Compare the feature map obtained above with the original template stored in the main control chip and calculate the correlation; Step 3-5. If the finger vein recognition passes, the data transmission path on the SATA / SAS side is opened. Otherwise, the finger vein recognition is repeated. If the authentication fails six times in a row, the wireless network communication module will send an error alarm to the communication device of the host bus adapter owner, the finger vein recognition module will be silent for 10 minutes, and the buzzer alarm will be triggered. When the finger vein recognition module is released from silent state, the alarm is lifted and authentication will be restarted from step 2.

4. A host bus adapter capable of implementing double-end encryption authentication, characterized in that: The double-end encryption authentication method according to any one of claims 1 to 3 is run, and its structure includes an HBA board body, a wireless network communication module, a finger vein recognition module and a buzzer; the HBA board body includes a main control chip, a power chip, a PCIe interface and a SATA / SAS interface; the main control chip is electrically connected to the wireless network communication module, the finger vein recognition module, the power chip, the PCIe interface and the SATA / SAS interface respectively; the wireless network communication module and the finger vein recognition module are both electrically connected to the buzzer.

Citation Information

Patent Citations

  • User real information security certification system and method

    CN107294961A

  • Data processing method and equipment based on independent encryption chip

    CN113127896A