Authentication method, controller and computer device
By generating a fusion feature digest through hash operations on the hardware and software parameters of computer equipment components, the problem of easy counterfeiting, tampering, or replacement of components is solved, thereby improving the security and reliability of components.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-07-28
- Publication Date
- 2026-04-07
AI Technical Summary
The fact that computer equipment components are manufactured by different companies makes it difficult to guarantee security and reliability, and makes them susceptible to counterfeiting, tampering, or replacement.
By performing at least two hash operations on the hardware and software parameters of the object to be authenticated, a fusion feature digest is generated. Authentication is then performed by combining the fusion feature digest indicated by the identifier, ensuring the compatibility and security of the components.
It improves the safety and reliability of components, prevents counterfeiting, tampering or replacement, and ensures the accuracy of component compatibility certification results.
Smart Images

Figure CN119046920B_ABST
Abstract
Description
[0001] This application claims priority to the Chinese Patent Application No. 202310617828.0, filed on May 29, 2023, and entitled "A certification method", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0002] The present application relates to the field of computers, and in particular to a certification method, a controller and a computer device. BACKGROUND
[0003] Generally, the performance of a computer device is measured by the configuration of the computer device, and the performance of the computer device is improved by expanding the types of components in the computer device. For example, increasing the types of processors in the computer device improves the diversity of computing power. For another example, increasing the types of memories in the computer device improves the diversity of storage, ensures the reliability of data, and enables the processor to obtain data as soon as possible. However, the components in the computer device can be produced by different manufacturers, and the types of manufacturers of the components are diversified. Moreover, products (such as components or software) are updated rapidly, and the components are easily counterfeited, tampered or replaced, which cannot guarantee the security and reliability of the components. SUMMARY
[0004] The present application provides a certification method, a controller and a computer device, thereby improving the security and reliability of the components.
[0005] In a first aspect, a certification method is provided. A feature of a to-be-certified object is obtained according to a hardware parameter and a software parameter of the to-be-certified object. The to-be-certified object is certified according to a fusion feature digest indicated by an identifier of the to-be-certified object and the feature of the to-be-certified object, to obtain a compatibility certification result of the to-be-certified object. The compatibility certification result includes a compatibility certification pass and a compatibility certification fail. The fusion feature digest is used to indicate that a component based on a fusion feature of the component passes a compatibility test. The fusion feature of the component is generated based on a hardware parameter and a software parameter of the component.
[0006] Compared with the problem that the security and reliability of a component cannot be guaranteed by only relying on the manufacturer's claim that the component passes a compatibility certification, the method provided by the present application acquires a fusion feature digest indicated by an identifier of a to-be-certified object, and verifies the feature of the to-be-certified object according to the fusion feature digest, i.e., compares the feature of the to-be-certified object with a reference feature of the to-be-certified object. If the to-be-certified object is counterfeited, tampered or replaced, the feature of the to-be-certified object can be different from the reference feature of the to-be-certified object, and the to-be-certified object can have a security and reliability risk. Therefore, the compatibility of the component is dynamically verified by security technology, thereby improving the security and reliability of the component.
[0007] The object to be authenticated can be any one of a memory, a circuit board, or a Peripheral Component Interconnect Express (PCIe).
[0008] In a possible implementation, the feature of the object to be authenticated is obtained based on the hardware parameter and the software parameter of the object to be authenticated, including performing at least two times of hash operations on the hardware parameter and the software parameter of the object to be authenticated to obtain the feature of the object to be authenticated.
[0009] Therefore, the feature of the object to be authenticated is generated based on the parameters inherent to the object to be authenticated, ensuring the security level of the feature of the object to be authenticated, and preventing the feature from being arbitrarily tampered with or obtained.
[0010] In some possible embodiments, the hardware parameter includes a hardware root of trust and an identifier of the object to be authenticated, and the software parameter includes a firmware digest of the object to be authenticated; the at least two times of hash operations on the hardware parameter and the software parameter of the object to be authenticated to obtain the feature of the object to be authenticated include: performing a hash operation on the hardware root of trust of the object to be authenticated to obtain a first hash value; performing a hash operation on the identifier and the first hash value to obtain a second hash value; and performing a hash operation on the firmware digest of the object to be authenticated and the second hash value to obtain the feature of the object to be authenticated.
[0011] Therefore, the feature of the object to be authenticated is generated based on the parameters inherent to the object to be authenticated, ensuring the security level of the feature of the object to be authenticated, and preventing the feature from being arbitrarily tampered with or obtained.
[0012] In some possible embodiments, the hardware parameter includes a hardware root of trust and an identifier of the object to be authenticated, and the software parameter includes a firmware digest of the object to be authenticated; the at least two times of hash operations on the hardware parameter and the software parameter of the object to be authenticated to obtain the feature of the object to be authenticated include: performing a hash operation on the hardware root of trust of the object to be authenticated to obtain a first hash value; performing a hash operation on the identifier and the first hash value to obtain a second hash value; and performing a hash operation on the firmware digest of the object to be authenticated and the second hash value to obtain the feature of the object to be authenticated.
[0013] Therefore, the feature of the object to be authenticated is generated based on the parameters inherent to the object to be authenticated, ensuring the security level of the feature of the object to be authenticated, and preventing the feature from being arbitrarily tampered with or obtained.
[0014] In another possible implementation, the fusion feature of the component is generated based on at least two times of hash operations on the hardware parameter and the software parameter of the component.
[0015] Therefore, the fusion feature of the component is generated based on the parameters inherent to the component, ensuring the security level of the fusion feature of the component, and preventing the fusion feature from being arbitrarily tampered with or obtained.
[0016] In some possible embodiments, the at least two times of hash operations on the hardware parameters and the software parameters of the component obtain the fusion feature of the component, including: performing a hash operation on the hardware trusted root of the component to obtain a first hash value; performing a hash operation on the identification and the first hash value to obtain a second hash value; and performing a hash operation on the firmware digest of the component and the second hash value to obtain the fusion feature of the component.
[0017] In some possible embodiments, the at least two times of hash operations on the hardware parameters and the software parameters of the component obtain the fusion feature of the component, including: performing a hash operation on the hardware trusted root of the component to obtain a first hash value; performing a hash operation on the identification and the first hash value to obtain a second hash value; and performing a hash operation on the firmware digest of the component and the second hash value to obtain the fusion feature of the component.
[0018] In another possible implementation, the object to be authenticated is authenticated according to the fusion feature digest indicated by the identification of the object to be authenticated and the feature of the object to be authenticated, including: decrypting the fusion feature digest according to the public key to obtain the fusion feature; and determining a compatibility authentication result of the object to be authenticated according to a comparison result of the fusion feature and the feature of the object to be authenticated.
[0019] Therefore, the fusion feature of the component is encrypted by using a signature method, for example, the fusion feature of the component is encrypted by using a signature key based on original compatibility authentication, so that the security of the fusion feature of the component is ensured, and the fusion feature of the component is prevented from being tampered with or obtained arbitrarily. In addition, the original compatibility list is changed and affected little, and the fusion feature option of the component is added to the original compatibility list.
[0020] For example, when the feature of the object to be authenticated is the same as the fusion feature, it is determined that the compatibility authentication result of the object to be authenticated indicates that the object to be authenticated passes the compatibility authentication; and when the feature of the object to be authenticated is different from the fusion feature, it is determined that the compatibility authentication result of the object to be authenticated indicates that the object to be authenticated fails the compatibility authentication.
[0021] In another possible implementation, the method further includes: obtaining the fusion feature digest and the public key from an electronic tag of the object to be authenticated, and the public key is used to decrypt the fusion feature digest.
[0022] Therefore, the fusion feature digest of the component is written in the electronic tag, the cost of the compatibility proof is reduced, the original component is changed little, and the security risks such as tampering or replacing of software and hardware are reduced.
[0023] In another possible implementation, the method further includes: obtaining the fusion feature digest and the public key from a compatibility list published by a manufacturer according to the identification of the object to be authenticated.
[0024] Therefore, the fusion feature digest of the component is added to the original compatibility list, the benchmark of the compatibility proof of the component is published, the evidence is easy to obtain, the private key is encrypted, and the integrity protection capability is possessed.
[0025] Secondly, an authentication device is provided, comprising: an authentication module, configured to obtain features of the object to be authenticated based on hardware and software parameters of the object to be authenticated; the authentication module is further configured to authenticate the object to be authenticated based on a fusion feature summary indicated by the identifier of the object to be authenticated and the features of the object to be authenticated, thereby obtaining a compatibility authentication result of the object to be authenticated, the compatibility authentication result including compatibility authentication passed and compatibility authentication failed, the fusion feature summary being used to indicate that the component-based fusion feature component has passed the compatibility test, the fusion feature of the component being generated based on the hardware and software parameters of the component.
[0026] In one possible implementation, when the authentication module obtains the characteristics of the object to be authenticated based on the hardware and software parameters of the object to be authenticated, it is specifically used to: perform at least two hash operations on the hardware and software parameters of the object to be authenticated to obtain the characteristics of the object to be authenticated.
[0027] In another possible implementation, the hardware parameters include the hardware root of trust and the identifier of the object to be authenticated, and the software parameters include the firmware digest of the object to be authenticated. When the authentication module performs at least two hash operations on the hardware and software parameters of the object to be authenticated to obtain its characteristics, it specifically performs the following: performs a hash operation on the hardware root of trust of the object to be authenticated to obtain a first hash value; performs a hash operation on the identifier and the first hash value to obtain a second hash value; and performs a hash operation on the firmware digest and the second hash value of the object to be authenticated to obtain its characteristics.
[0028] In another possible implementation, the hardware parameters include an identifier, and the software parameters include a firmware digest of the object to be authenticated;
[0029] When the authentication module performs at least two hash operations on the hardware and software parameters of the object to be authenticated to obtain the characteristics of the object to be authenticated, it is specifically used to: perform a hash operation on the identifier to obtain a first hash value; and perform a hash operation on the firmware digest of the object to be authenticated and the first hash value to obtain the characteristics of the object to be authenticated.
[0030] In another possible implementation, the fusion feature of the component is generated based on at least two hash operations on the component's hardware and software parameters.
[0031] In another possible implementation, when the authentication module authenticates the object to be authenticated based on the fusion feature digest indicated by the identifier of the object to be authenticated and the features of the object to be authenticated, it is specifically used to: decrypt the fusion feature digest using the public key to obtain the fusion feature; and determine the compatibility authentication result of the object to be authenticated based on the comparison result between the fusion feature and the features of the object to be authenticated.
[0032] In another possible implementation, the device further includes a communication module for obtaining a fusion feature digest and a public key from the electronic tag of the object to be authenticated.
[0033] In another possible implementation, the device further includes a communication module; the communication module is used to obtain a fusion feature digest and a public key from a compatibility list published by the vendor based on the identifier of the object to be authenticated.
[0034] In another possible implementation, the object to be authenticated includes any one of a memory, a circuit board, or a PCIe card.
[0035] Thirdly, a controller is provided, including logic circuitry and a power supply circuit; wherein the power supply circuitry supplies power to the logic circuitry; and the logic circuitry is used to perform operational steps of the method as described in the first aspect or any possible implementation thereof. For example, the logic circuitry is a Baseboard Management Controller (BMC).
[0036] Fourthly, a computer device is provided, comprising a memory, a controller, and multiple components, wherein the memory stores a set of computer instructions; when the controller executes the set of computer instructions, it performs the operation steps of the method described in the first aspect or any possible implementation of the first aspect, thereby achieving compatibility authentication of the multiple components.
[0037] Fifthly, a communication system is provided, comprising a remote device and a computer device. The remote device is used to perform operational steps of the method described in the first aspect or any possible implementation thereof, to achieve compatibility authentication of multiple components in the computer device.
[0038] A sixth aspect provides a computer-readable storage medium comprising: computer software instructions; which, when executed in a computer device, cause the computer device to perform operational steps of the method as described in the first aspect or any possible implementation thereof.
[0039] In a seventh aspect, a computer program product is provided that, when run on a computer, causes the computer to perform the operational steps of the method as described in the first aspect or any possible implementation thereof.
[0040] The technical effects of any of the design approaches in aspects two through seven can be found in the technical effects of aspects one or different possible implementations of aspects one, and will not be repeated here.
[0041] Based on the implementation methods provided in the above aspects, this application can be further combined to provide more implementation methods. Attached Figure Description
[0042] Figure 1 A schematic diagram of the structure of a computer device provided in this application;
[0043] Figure 2 A schematic diagram illustrating a scenario for performing compatibility authentication provided in this application;
[0044] Figure 3 A flowchart illustrating an authentication method provided for this application;
[0045] Figure 4 A schematic diagram illustrating the extraction of features of a component provided in this application;
[0046] Figure 5 A schematic diagram illustrating the extraction of fusion features of a component provided in this application;
[0047] Figure 6 A flowchart illustrating another authentication method provided for this application;
[0048] Figure 7 A flowchart illustrating another authentication method provided for this application;
[0049] Figure 8 A schematic diagram of a message format provided for this application;
[0050] Figure 9 A schematic diagram illustrating the interface display of a compatibility list provided in this application;
[0051] Figure 10 A flowchart illustrating another authentication method provided for this application;
[0052] Figure 11 A schematic diagram of the structure of an authentication device provided in this application;
[0053] Figure 12 A schematic diagram of the structure of a controller provided in this application;
[0054] Figure 13 A schematic diagram of another controller provided in this application. Detailed Implementation
[0055] To facilitate understanding, the main terms used in this application will be explained first.
[0056] Compatibility refers to the degree of coordination between hardware, software, or combined hardware and software systems. For example, if hardware components (such as the central processing unit (CPU), motherboard, and graphics card) can work together stably, their compatibility is high; conversely, if they cannot, their compatibility is low. Similarly, if software can run stably on several operating systems without unexpected malfunctions, its compatibility is high; conversely, if it cannot, its compatibility is low.
[0057] Trusted root: Also known as the root of trust, it serves as the basis of trust in a trusted computer system. Trusted roots include trusted measurement roots, trusted storage roots, and trusted reporting roots.
[0058] Hardware root of trust: refers to a root of trust based on the tamper-proof capabilities of chips or hardware, and is used to protect the integrity of hardware and firmware through trusted chain technology.
[0059] Firmware refers to the hardware "drivers" stored internally within hardware, which determine the hardware's functionality and performance. Through firmware, the operating system implements specific machine operations according to standard hardware drivers; for example, optical drives and CD burners store internal firmware. Firmware is typically stored in erasable programmable read-only memory (EPROM) or electrically erasable programmable read-only memory (EEPROM).
[0060] Firmware summary: refers to the hash value obtained by performing a hash operation on the firmware, and the value obtained by encrypting the hash value based on the private key.
[0061] Motherboard: Also known as mainboard, system board, or motherboard, it is one of the most basic and important components of a computer. A motherboard can be a circuit board containing the main circuitry of the computer, typically including a Basic Input Output System (BIOS) chip, input / output (I / O) control chips, keyboard and front panel control switch interfaces, indicator light connectors, expansion slots, DC power supply connectors, and other components.
[0062] Network Interface Card (NIC): Also known as a network adapter or network interface card. A NIC is a piece of hardware used to connect a computer to an external local area network (LAN), allowing the computer to communicate with other devices on the computer network.
[0063] Baseboard Management Controller (BMC): A dedicated controller integrated on the motherboard or plugged into the motherboard via a standard such as Peripheral Component Interconnect Express (PCIe), used for monitoring and managing servers. Examples include device information management, server status monitoring and management, remote server control management, and maintenance management.
[0064] To address the security and reliability issues of components in scenarios where component manufacturers are diverse and components are easily counterfeited, tampered with, or replaced, this application provides an authentication method. This method involves obtaining the characteristics of the object to be authenticated based on its hardware and software parameters; authenticating the object based on a fusion feature digest indicated by its identifier and these characteristics; and obtaining a compatibility authentication result, which includes either successful or unsuccessful compatibility authentication. The fusion feature digest indicates whether the component-based fusion feature has passed compatibility testing. The component's fusion feature is generated based on its hardware and software parameters.
[0065] Compared to relying solely on manufacturers' claims of component compatibility certification, which fails to guarantee component security and reliability, the method provided in this application obtains a fused feature digest based on the identifier of the object to be certified. This digest is then used to verify the characteristics of the object to be certified; specifically, it compares the characteristics of the object to be certified with its baseline characteristics. If the object to be certified has been counterfeited, tampered with, or replaced, its characteristics may differ from its baseline characteristics, potentially posing a security and reliability risk. Therefore, by dynamically verifying component compatibility through security technology, the security and reliability of the components are improved.
[0066] The object to be authenticated can be a component within a computer device. For example, it can be an independent device, such as memory or a processor. Memory includes Dynamic Random Access Memory (DRAM), Solid State Disk (SSD), and Storage-Class Memory (SCM). Processors can be computing units with computational capabilities, such as a Central Processing Unit (CPU), Graphics Processing Unit (GPU), Data Processing Unit (DPU), or Neural Processing Unit (NPU). Alternatively, the object to be authenticated can be a board composed of multiple components within a computer device. For example, it can include a circuit board or a PCIe card. A circuit board can be a motherboard, base board, or expansion board, and it may integrate a CPU, BMC, BIOS chip, and I / O control chip. PCIe cards include network cards, Artificial Intelligence (AI) cards, read cards, GPUs, DPUs, and NPUs.
[0067] The certification scheme provided in this application can be applied to traditional computer equipment that provides computing and storage functions, providing compatibility certification for components in traditional computer equipment, and can also be applied to servers in cluster networks. For example, in high-performance computing (HPC) networks, computing servers provide high-performance computing, and the components in the computing servers undergo compatibility certification to ensure the reliability of the computing servers.
[0068] The implementation method of the authentication method provided in this application will be described in detail below with reference to the accompanying drawings.
[0069] Figure 1 This is a schematic diagram of the structure of a computer device provided in this application. Figure 1 As shown, the computer device 100 includes a circuit board 110, a bus 120, a memory 130, a PCIe card 140, and a BMC 150. The circuit board 110, memory 130, PCIe card 140, and BMC 150 are connected via the bus 120.
[0070] In some embodiments, the circuit board 110 includes a processor 111, a memory unit 112, and a communication interface 113.
[0071] Processor 111 is the control center of computer device 100. Processor 111 can be a computing unit with computing capabilities, such as a CPU, GPU, DPU, or NPU. Processor 111 includes one or more processor cores. For example, Figure 1 The processor 111 shown contains N processor cores.
[0072] In some embodiments, the processor 111 includes a register 11 and a cache memory 12.
[0073] The cache memory 12 is used to store instructions or data that the processor core in the processor 111 may access multiple times. This improves the speed at which the processor processes data and avoids frequent accesses of the processor to the memory unit 112.
[0074] In terms of physical form, the cache memory 12 can be random access memory (RAM), static random-access memory (SRAM), dynamic random-access memory (DRAM), or other types of storage devices that can store information and instructions.
[0075] Logically, the cache memory 12 can be a Level 1 cache, a Level 2 cache, a Level 3 cache, or any level of cache device. For example, such as... Figure 1 As shown, the cache memory 12 located inside the processor core can be a level 1 cache (L1 cache) and a level 2 cache (L2 cache). The cache memory 12 located outside the processor core can be a level 3 cache (L3 cache).
[0076] Register 11 is used to store instructions or data that the processor core in processor 111 may access multiple times. Since the access speed of registers is higher than that of cache memory, instructions or data that the processor core may access multiple times can be stored in registers first, which can further improve the speed of processor data processing.
[0077] Optionally, the processor 111 can also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor, etc.
[0078] Memory unit 112 (also referred to as main memory unit) can be a pool of volatile memory or a pool of non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).
[0079] Communication interface 113 is used to enable communication between computer device 100 and external devices or components. In this application, computer device 100 can obtain a fusion feature summary from the component manufacturer's server through communication interface 113.
[0080] The memory 130 can be a persistent storage medium, such as a disk, like a hard disk drive or a solid-state drive.
[0081] PCIe card 140 can refer to peripherals. For example, PCIe card 140 includes network cards, etc.
[0082] In this application, memory unit 112 can be used to store the compatibility authentication instructions or data described in this application, such as a fused feature summary indicating the characteristics of the object to be authenticated and the identifier of the object to be authenticated. Memory 130 stores the compatibility authentication instructions or data.
[0083] Bus 120 may include a pathway for transmitting information between the aforementioned components (such as circuit board 110, PCIe card 140, BMC 150, and memory 130). In addition to a data bus, bus 120 may also include a power bus, control bus, and status signal bus. However, for clarity, all buses are labeled as bus 120 in the figure. Bus 120 may be a Peripheral Component Interconnect Express (PCIe) bus, or an Extended Industry Standard Architecture (EISA) bus, a unified bus (Ubus or UB), a compute express link (CXL), a cache coherent interconnect for accelerators (CCIX), etc. Bus 120 can be divided into address bus, data bus, control bus, etc.
[0084] It is worth noting that, Figure 1 Taking computer device 100 as an example, which includes a circuit board 110 and a memory 130, the circuit board 110 and the memory 130 are used to indicate a type of device or equipment. In specific embodiments, the quantity of each type of device or equipment can be determined according to business needs.
[0085] Figure 1 The device structure shown does not constitute a limitation on the computer device and may include more or fewer components than illustrated, or combine certain components, or have different component arrangements. For example, a computer device may also include artificial intelligence cards, read cards, GPUs, DPUs, and NPUs.
[0086] The components described in this application may include processors, memory, memory units, registers, cache memory, network interface cards (NICs), and circuit boards, etc., found in computer devices. The manufacturers of the components in a computer device may differ. During computer device startup, compatibility authentication is performed on the components contained within the computer device. For example, the characteristics of the object to be authenticated are obtained based on its hardware and software parameters; the compatibility authentication of the object is determined to be successful or unsuccessful based on the fused feature digest and the characteristics of the object to be authenticated.
[0087] Furthermore, this application does not limit the entity performing the compatibility certification. The computer equipment itself may perform compatibility certification on the components it contains, or a remote device may perform compatibility certification on the components contained in the computer equipment.
[0088] For example, such as Figure 2 As shown in (a), remote device 200 performs compatibility authentication on components included in computer device 100. Remote device 200 may be a management controller in the system, such as a controller in a data center. Specifically, remote device 200 obtains a convergence feature summary of the components released by the manufacturer, and receives features of the object to be authenticated reported by the computer device. Based on the convergence feature summary and the features of the object to be authenticated, it determines whether the compatibility authentication of the object to be authenticated has passed or failed.
[0089] like Figure 2 As shown in (b), the local device performs compatibility certification on the included components. For example, the computer device includes a baseboard management controller (BMC) 150. The baseboard management controller 150 obtains a convergence feature summary of the components released by the manufacturer, and obtains the features of the object to be certified within the computer device, and determines whether the object to be certified passes or fails compatibility certification based on the convergence feature summary and the features of the object to be certified.
[0090] The authentication method provided in this application will now be described in detail with reference to the accompanying drawings.
[0091] For ease of explanation, Figure 2 The remote authentication scenario shown in (a) illustrates this, using the example of a remote device 200 performing compatibility authentication on components contained in a computer device. (See also...) Figure 3 , Figure 3 This is a flowchart illustrating an authentication method provided in this application. Figure 3 As shown, the method includes the following steps.
[0092] Step 310: Obtain the characteristics of the object to be authenticated.
[0093] When a computer device starts up, it performs compatibility authentication on the components it contains. The object to be authenticated can be a component contained in the computer device, which can be an independent device in the computer device or a board composed of multiple devices in the computer device. In some embodiments, the computer device obtains the characteristics of the component based on the hardware and software parameters of the component in the computer device, reports the characteristics of the component to a remote device, and the remote device obtains the characteristics of the component reported by the computer device (step 310a).
[0094] In other embodiments, the remote device receives hardware and software parameters of components in the computer device reported by the computer device, and obtains the characteristics of the components based on the hardware and software parameters of the components in the computer device (step 310b).
[0095] The hardware parameters include the component's root of trust and identifier. The software parameters include the firmware digest of the object to be authenticated.
[0096] Remote devices or computer devices can perform at least two hash operations on the hardware and software parameters of a component to obtain the component's characteristics.
[0097] In some embodiments, such as Figure 4 As shown in (a), firstly, chip features are extracted. For example, a hash operation is performed on the hardware root of trust of the component to obtain a first hash value. Secondly, the chip features are extracted and the board features are fused to form an identity. For example, a hash operation is performed on the identifier and the first hash value to obtain a second hash value. The identifier can be the board's Equipment Serial Number (ESN), Board Identifier (Board ID), or an equivalent Original Equipment Manufacturer (OEM) Key. Finally, firmware features are extracted. For example, a hash operation is performed on the component's firmware to obtain a firmware digest, and a hash operation is performed on the component's firmware digest and the second hash value to obtain the component's features.
[0098] In other embodiments, such as Figure 4 As shown in (b), firstly, board features are extracted. For example, a hash operation is performed on the identifier to obtain a first hash value. Secondly, firmware features are extracted. For example, a hash operation is performed on the firmware of the component to obtain a firmware digest, and a hash operation is performed on the firmware digest and the first hash value of the component to obtain the features of the component.
[0099] Because information such as the hardware root of trust is programmed into the component's storage medium (e.g., EFUSE or OTP), it possesses physical tamper-proof capabilities. The identifier uniquely identifies the component and serves as its identity information. Thus, based on the component's hardware and software parameters, its characteristics are obtained, with the hardware root of trust ensuring the integrity of these characteristics. The identifier ensures the uniqueness of the component's characteristics. The firmware digest ensures the confidentiality of the component's characteristics.
[0100] Alternatively, the aforementioned hardware root of trust can be replaced with an equivalent hardware root of trust, such as a component's chip identifier (Die ID or Chip ID). The chip identifier uniquely identifies a chip and is its identification number.
[0101] Step 320: Authenticate the object to be authenticated based on the fusion feature summary indicated by the identifier of the object to be authenticated and the features of the object to be authenticated, and obtain the compatibility authentication result of the object to be authenticated.
[0102] Component manufacturers can generate a fusion feature for a component based on its hardware and software parameters. They then calculate a fusion feature digest using a private key. Based on this digest, the component passes compatibility testing, and the fusion feature digest and public key are published on the compatibility list. The fusion feature digest serves to prove the component's unique identity and indicates that the component passes compatibility testing based on its fusion features.
[0103] For example, performing at least two hash operations on the hardware and software parameters of a component yields the component's fused characteristics. For instance, such as... Figure 5 As shown in (a), a hash operation is performed on the hardware root of trust of the component to obtain a first hash value; a hash operation is performed on the identifier and the first hash value to obtain a second hash value; a hash operation is performed on the firmware digest of the component and the second hash value to obtain the fusion feature of the component. Figure 5 As shown in (b), a hash operation is performed on the identifier to obtain a first hash value; a hash operation is performed on the firmware digest of the component and the first hash value to obtain the fusion feature of the component.
[0104] It should be noted that the component fusion characteristics are generated based on the hardware and software parameters of the components manufactured by the manufacturer. These fusion characteristics can serve as benchmark information for component compatibility certification.
[0105] The remote device obtains the characteristics and identifiers of the components reported by the computer device, and obtains the fusion feature summary of the components based on the component identifiers.
[0106] In some embodiments, such as Figure 6As shown, based on the component's identifier, the component's fusion feature digest and public key are obtained from the manufacturer's published compatibility list (step 321). The fusion feature digest is decrypted using the public key to obtain the fusion feature (step 322). The component's compatibility authentication result is determined based on the comparison result between the fusion feature and the component's features (step 323). The compatibility authentication result includes compatibility authentication passed and compatibility authentication failed. For example, when the component's features are the same as the fusion feature, the component's compatibility authentication result indicates that the component's compatibility authentication has passed; when the component's features are different from the fusion feature, the component's compatibility authentication result indicates that the component's compatibility authentication has failed.
[0107] In other embodiments, such as Figure 7 As shown, the component's fusion feature digest and public key are stored in the component's electronic tag. For example, the electronic tag can be programmed into the storage medium 160 of the computer device 100 (e.g., EFUSE or OTP). The computer device retrieves the component's fusion feature digest and public key from the electronic tag and reports the component's fusion feature digest and public key to a remote device (step 324). The remote device receives the component's fusion feature digest and public key reported by the computer device.
[0108] Optionally, the remote device can also report the component compatibility certification results to the computer device.
[0109] In a modular hardware system design, components can be developed independently by component manufacturers and partners. However, because components in computer equipment can be counterfeited, tampered with, or replaced, the characteristics of these components may differ from their integrated characteristics. Therefore, using the integrated characteristics of components as benchmark information, the aforementioned certification process automatically determines whether a component has passed compatibility certification. This improves the security and reliability of components compared to relying solely on manufacturers' claims of compatibility certification.
[0110] Understandably, the method for generating the features of a component should be the same as the method for generating the fused features of the component. If a component is counterfeited, altered, or replaced, the features of the component may differ from the fused features of the component, and the component may pose a security and reliability risk.
[0111] Optionally, the compatibility list may also include part codes. The computer device may also report part codes to remote devices. For example, such as... Figure 8 The diagram shown illustrates a message format provided in this application. The message includes the component's identifier, component code, and component characteristics. The remote device retrieves the component's fusion feature digest and public key from the manufacturer's compatibility list based on the component's identifier and component code.
[0112] For example, Figure 9 This is a schematic diagram illustrating the interface display of a compatibility list provided in this application. For example... Figure 9As shown in (a), the component compatibility query interface displays option boxes for product model, network card type, network card model, and component type. Enter the content for each option box and click the "Query" button to display the compatibility list. Figure 9 As shown in (b) above, this is a schematic diagram of the compatibility list display. The contents of the compatibility list are displayed based on the selected item. For example, the compatibility list may include items such as encoding, encoding type, card type, model, description, interface type, and compatibility certification. The compatibility certification item contains the component's fusion feature digest and public key.
[0113] It is worth noting that, for Figure 2 In the local authentication scenario shown in (b), that is, when a computer device performs compatibility authentication on the components contained in the computer device, the authentication process is similar to... Figure 2 The authentication process is similar to (a) in the example. The difference is that the computer device does not need to report the characteristics of the component or the hardware and software parameters of the component to the remote device. Instead, the computer device obtains the characteristics of the component based on its hardware and software parameters, and obtains the component's integrated characteristics based on the component's identifier. It then compares the component's characteristics with the integrated characteristics to determine the component's compatibility authentication result. For example, as... Figure 10 As shown, when the computer device starts up, the BMC obtains the hardware and software parameters of the components, obtains the characteristics of the components based on the hardware and software parameters (step 1010), and obtains the fusion characteristics of the components according to the component's identifier. The BMC compares the component's characteristics with the fusion characteristics to determine the component's compatibility certification result (step 1020). Specifically, the BMC can obtain the component's fusion characteristic digest and public key from the compatibility list published by the manufacturer based on the component's identifier. Alternatively, the BMC can obtain the component's fusion characteristic digest and public key from the component's electronic tag. For simplicity, only the following is used here: Figure 2 Taking scenario (a) as an example, the authentication process in other scenarios is similar. Figure 3 The authentication process shown is similar and can be referred to the description in the above embodiments, so it will not be repeated here.
[0114] It should be noted that the above Figure 4 The method for generating features of the component shown and Figure 5The method for generating the fusion feature of the component shown is merely illustrative. In practical applications, other methods can be used to generate the component's features and fusion features. For example, the order in which the hardware and software parameters are performed on hash operations can be changed. For instance, a hash operation is performed on the component's hardware root of trust to obtain a first hash value; a hash operation is performed on the component's firmware digest and the first hash value to obtain a second hash value; a hash operation is then performed on the identifier and the second hash value to obtain the component's fusion feature or feature. Alternatively, at least two hash operations can be performed on the hardware parameters, software parameters, and a random number of the object to be authenticated to obtain the component's fusion feature or feature. The component's electronic tag contains a random number, or the manufacturer's compatibility list contains a random number. This allows remote devices or computer devices to obtain random numbers from the electronic tag or compatibility list to generate the component's fusion feature or feature. This further enhances the security level of the component's fusion feature or feature, improving the component's security and reliability.
[0115] Furthermore, this application does not limit the format of any of the parameters, including hardware parameters, software parameters, fusion features, features, and hash values. They can be text, numbers, or binary values, etc.
[0116] For each component within a computer device, compatibility certification can be performed using the certification method provided in this application. The relevant steps are described in the above embodiments and will not be repeated here.
[0117] The authentication method provided in this application can be executed when a computer device starts up or when a component within the computer device starts up. When the computer device starts up, the authentication method provided in this application performs compatibility authentication on the components within the computer device to ensure the security and reliability of the components. When a component starts up, the authentication method provided in this application performs compatibility authentication on the component. For example, when a component restarts and is reconnected to the computer device, the authentication method provided in this application performs compatibility authentication on the component. Similarly, when an original component is replaced and the new component is reconnected to the computer device, the authentication method provided in this application performs compatibility authentication on the new component.
[0118] In other embodiments, the authentication method provided in this application can be applied not only to perform compatibility authentication on components within a computer device, but also to perform compatibility authentication on the entire machine. For example, the BMC obtains the component's fusion feature digest and public key from the electronic tag of each component, decrypts the fusion feature digest using the public key to obtain the fusion feature, and compares the fusion feature with the component's features to obtain the component's compatibility authentication result, thereby realizing compatibility authentication for each component running in a single computer device. Optionally, the server's backplane memory stores the entire machine's electronic tag, and the BMC can obtain the fusion feature digest and public key of each component from the entire machine's electronic tag to perform compatibility authentication on each component separately. Optionally, the entire machine's electronic tag contains the entire machine's fusion feature digest and public key. The entire machine's fusion feature digest can be obtained by performing a hash operation based on the attributes of multiple components in the computer device. For example, a hash operation is performed on the hardware and software parameters of components such as circuit boards, memory, and PCIe boards in the computer device to obtain the entire machine's fusion feature of multiple components, and then the entire machine's fusion feature digest is calculated based on the entire machine's fusion feature obtained using the private key. BMC decrypts the overall system integration feature digest using the public key to obtain the overall system integration feature. It then compares the overall system integration feature with the overall system features of multiple components to obtain the overall system compatibility certification result, thereby enabling overall system compatibility certification of multiple components in a computer device.
[0119] It is understood that, in order to achieve the functions in the above embodiments, the device includes hardware structures and / or software modules corresponding to each function. Those skilled in the art should readily recognize that, based on the units and method steps of the various examples described in conjunction with the embodiments disclosed in this application, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed by hardware or by computer software driving hardware depends on the specific application scenario and design constraints of the technical solution.
[0120] The above text combines Figures 1 to 10 The application details the authentication method provided in this application, which will be discussed below in conjunction with... Figure 10 This describes the authentication device provided according to this application.
[0121] Figure 11 This is a schematic diagram of a possible authentication device provided in this application. These authentication devices can be used to implement the functions of remote devices or computer devices in the above method embodiments, and therefore can also achieve the beneficial effects of the above method embodiments. In this embodiment, the authentication device can be as follows: Figure 1 The device shown can also be a module (such as a chip) used in servers.
[0122] like Figure 11As shown, the authentication device 1100 includes a communication module 1110, an authentication module 1120, and a storage module 1130. The authentication device 1100 is used to implement the above-mentioned... Figure 3 , Figure 6 , Figure 7 or Figure 10 The method embodiments shown illustrate the functionality of the remote device or computer device.
[0123] like Figure 11 As shown in (a), the authentication device 1100 is used to implement the above. Figure 3 , Figure 6 , Figure 7 The method embodiment shown illustrates the functionality of the remote device.
[0124] Communication module 1110 is used to acquire hardware and software parameters or characteristics of the object to be authenticated. For example, communication module 1110 is used to execute... Figure 3 Step 310.
[0125] The communication module 1110 is also used to provide feedback on compatibility certification results to computer devices.
[0126] The authentication module 1120 is used to obtain the characteristics of the object to be authenticated based on its hardware and software parameters. For example, the authentication module 1120 is used to execute... Figure 3 Step 310b.
[0127] Authentication module 1120 is used to authenticate the object to be authenticated based on the fused feature digest indicated by the identifier of the object to be authenticated and the features of the object to be authenticated, thereby obtaining a compatibility authentication result for the object to be authenticated. For example, authentication module 1120 is used to perform... Figure 3 Step 320.
[0128] Optionally, the authentication module 1120 has the feature of performing at least two hash operations on the hardware parameters and software parameters of the object to be authenticated to obtain the object to be authenticated.
[0129] Storage module 1130 is used to store the converged feature digest and public key to facilitate the execution of the compatibility authentication process.
[0130] like Figure 11 As shown in (b), the authentication device 1100 is used to implement the above. Figure 10 The method embodiment shown illustrates the function of the computer device.
[0131] Communication module 1110 is used to obtain the fusion feature digest and public key from the compatibility list.
[0132] The authentication module 1120 is used to obtain the characteristics of the object to be authenticated based on its hardware and software parameters. For example, the authentication module 1120 is used to execute...Figure 10 Step 1010.
[0133] Authentication module 1120 is used to authenticate the object to be authenticated based on the fused feature digest indicated by the identifier of the object to be authenticated and the features of the object to be authenticated, thereby obtaining a compatibility authentication result for the object to be authenticated. For example, authentication module 1120 is used to perform... Figure 10 Step 1020.
[0134] Storage module 1130 is used to store the characteristics, fused characteristic digests and public keys of the object to be authenticated, so as to facilitate the execution of the compatibility authentication process.
[0135] It should be understood that the authentication device 1100 in this application embodiment can be implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD can be a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. It can also be implemented using software. Figure 3 , Figure 6 , Figure 7 or Figure 10 The authentication method shown, and its modules, can also be software modules, as can the authentication device 1100 and its modules.
[0136] The authentication device 1100 according to the embodiments of this application can correspondingly execute the methods described in the embodiments of this application, and the above and other operations and / or functions of each unit in the authentication device 1100 are respectively for implementing Figure 3 , Figure 6 , Figure 7 or Figure 10 For the sake of brevity, the corresponding processes of each method in the code will not be elaborated here.
[0137] Figure 12 This is a schematic diagram of the structure of a controller 1200 provided in this application. Figure 12 As shown, the controller 1200 includes a processor 1210, a bus 1220, a memory 1230, a communication interface 1240, and a memory unit 1250 (also referred to as a main memory unit). The processor 1210, memory 1230, memory unit 1250, and communication interface 1240 are connected via the bus 1220.
[0138] It should be understood that in this embodiment, the processor 1210 may be a CPU, but it may also be other general-purpose processors, digital signal processors (DSPs), ASICs, FPGAs, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.
[0139] The communication interface 1240 is used to enable communication between the controller 1200 and external devices or components. In this application, the controller 1200 is used to implement... Figure 3 , Figure 6 , Figure 7 When the remote device is shown to function, the communication interface 1240 is used to acquire the fused feature digest, public key, and features of the object to be authenticated, so that the processor 1210 can authenticate the object to be authenticated based on the fused feature digest and the features of the object to be authenticated, and obtain the compatibility authentication result of the object to be authenticated. The controller 1200 is used to implement... Figure 10 When the computer device shown functions, the communication interface 1240 is used to obtain the fusion feature digest and public key, so that the processor 1210 can authenticate the object to be authenticated based on the fusion feature digest and the features of the object to be authenticated, and obtain the compatibility authentication result of the object to be authenticated.
[0140] Bus 1220 may include a pathway for transmitting information between the aforementioned components (such as processor 1210, memory unit 1250, and memory 1230). In addition to a data bus, bus 1220 may also include a power bus, control bus, and status signal bus. However, for clarity, all buses are labeled as bus 1220 in the figure. Bus 1220 may be a Peripheral Component Interconnect Express (PCIe) bus, or an Extended Industry Standard Architecture (EISA) bus, a unified bus (Ubus or UB), a compute express link (CXL), a cache coherent interconnect for accelerators (CCIX), etc. Bus 1220 can be divided into address bus, data bus, control bus, etc.
[0141] As an example, controller 1200 may include multiple processors. A processor may be a multi-core (multi-CPU) processor. Here, a processor may refer to one or more devices, circuits, and / or computing units used to process data (e.g., computer program instructions).
[0142] It is worth noting that, Figure 12 Taking the controller 1200 as an example, which includes one processor 1210 and one memory 1230, the processor 1210 and the memory 1230 are used to indicate a type of device or equipment. In specific embodiments, the number of each type of device or equipment can be determined according to business requirements.
[0143] Memory cell 1250 may be a pool of volatile memory or a pool of non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory may be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM). Memory cell 1250 is used to store the characteristics of the object to be authenticated, a fused characteristic digest, a public key, compatibility authentication results, etc.
[0144] The memory 1230 can correspond to the storage medium used in the above method embodiments to store information such as the characteristics, fused feature digest, and public key of the object to be authenticated, such as a disk, like a mechanical hard disk or a solid-state hard disk.
[0145] It should be understood that the controller 1200 according to this embodiment can correspond to the authentication device 1100 in this embodiment, and can correspond to the execution according to Figure 3, Figure 6 , Figure 7 or Figure 10 The corresponding subject in any of the methods, and the above and other operations and / or functions of each module in the authentication device 1100 are respectively for the purpose of implementing Figure 3 , Figure 6 , Figure 7 or Figure 10 For the sake of brevity, the corresponding processes of each method in the code will not be elaborated here.
[0146] Figure 13 This is a schematic diagram of the structure of a controller 1300 provided in this application. Figure 13 As shown, the controller 1300 includes a logic circuit 1310 and a power supply circuit 1320; wherein, the power supply circuit 1320 is used to supply power to the logic circuit 1310; the logic circuit 1310 is used to execute the operation steps of the authentication method described in the above method embodiments.
[0147] This application provides a communication system, which includes a remote device and a computer device. The computer device includes multiple components. The remote device is used to execute the operation steps of the authentication method described in the above method embodiments to achieve compatibility authentication of multiple components.
[0148] The method steps in this embodiment can be implemented in hardware or by a processor executing software instructions. The software instructions can consist of corresponding software modules, which can be stored in random access memory (RAM), flash memory, read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, hard disks, portable hard disks, CD-ROMs, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and storage medium can reside in an ASIC. Alternatively, the ASIC can reside in a computing device. Of course, the processor and storage medium can also exist as discrete components in the computing device.
[0149] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of this application are performed entirely or partially. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user equipment, or other programmable device. The computer program or instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; it can also be an optical medium, such as a digital video disc (DVD); or it can be a semiconductor medium, such as a solid-state drive (SSD). The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. An authentication method, characterized in that, include: The characteristics of the object to be authenticated are obtained based on its hardware and software parameters. The object to be certified is certified based on the fusion feature digest indicated by the identifier of the object to be certified and the features of the object to be certified, and a compatibility certification result of the object to be certified is obtained. The compatibility certification result includes compatibility certification passed and compatibility certification failed. The fusion feature digest is used to indicate that the component-based fusion features have passed the compatibility test. The component fusion features are generated based on the hardware parameters and software parameters of the component. The hardware parameters include the hardware root of trust of the object to be authenticated and the identifier, and the software parameters include the firmware digest of the object to be authenticated; Performing at least two hash operations on the hardware and software parameters of the object to be authenticated to obtain the characteristics of the object to be authenticated, including: A hash operation is performed on the hardware root of trust of the object to be authenticated to obtain a first hash value; Perform a hash operation on the identifier and the first hash value to obtain a second hash value; A hash operation is performed on the firmware digest of the object to be authenticated and the second hash value to obtain the characteristics of the object to be authenticated.
2. The method according to claim 1, characterized in that, The fusion feature of the component is generated based on at least two hash operations on the hardware and software parameters of the component.
3. The method according to claim 1 or 2, characterized in that, Authenticating the object to be authenticated based on the fused feature digest indicated by the identifier of the object to be authenticated and the features of the object to be authenticated, including: The fusion feature is obtained by decrypting the fusion feature digest using the public key; The compatibility authentication result of the object to be authenticated is determined based on the comparison result between the fusion feature and the feature of the object to be authenticated.
4. The method according to claim 1 or 2, characterized in that, The method further includes: The fusion feature digest and public key are obtained from the electronic tag of the object to be authenticated, and the public key is used to decrypt the fusion feature digest.
5. The method according to claim 1 or 2, characterized in that, The method further includes: Based on the identifier of the object to be authenticated, the fusion feature digest and public key are obtained from the compatibility list published by the manufacturer, and the public key is used to decrypt the fusion feature digest.
6. The method according to claim 1 or 2, characterized in that, The object to be certified includes any one of memory, circuit board, or PCIe card (Quick Peripheral Component Interconnect Standard).
7. A controller, characterized in that, The controller includes a logic circuit and a power supply circuit; wherein the power supply circuit is used to supply power to the logic circuit; the logic circuit is used to execute the operation steps of the method according to any one of claims 1-6.
8. The controller according to claim 7, characterized in that, The logic circuitry includes a baseboard management controller (BMC) or a control unit.
9. A computer device, characterized in that, The computer device includes a memory, a controller, and multiple components. The memory is used to store a set of computer instructions. When the controller executes the set of computer instructions, it performs the operation steps of the method according to any one of claims 1-6 to achieve compatibility authentication of the multiple components.
Citation Information
Patent Citations
System for verification of integrity of unmanned aerial vehicles
CN109392310A
Authentication certificate generation method and device, and equipment authentication method and device
CN114124394A