Authentication method and device, storage medium and electronic equipment

By introducing time factors in the device authentication process, the slave device periodically generates authentication data and sends the latest data to the master device at a preset time point, the problem that the authentication process in the prior art is easily simulated and copied, and the security of the authentication process is improved.

CN119996054AActive Publication Date: 2025-05-13GUANGZHOU ZHONO ELECTRONICS TECH CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510312386.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-05-13
Estimated Expiration
2045-03-14

AI Technical Summary

Technical Problem

The authentication process in the prior art is easy to be simulated and copied by attackers due to the fixed operation results, resulting in a lack of security in the authentication process.

Method used

The time factor is introduced during the authentication process, so that the slave device periodically generates authentication data through a fixed algorithm, and sends the latest authentication data to the master device at a preset time point. The master device determines whether the slave device passes authentication by comparing the expected data at the preset time point with the actual data.

Benefits of technology

By adding time factors, the authentication process no longer depends on static data and keys, thereby increasing the difficulty of attackers to crack and improving the security of the authentication process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996054A_ABST
    Figure CN119996054A_ABST
Patent Text Reader

Abstract

The invention provides an authentication method and device, a storage medium and electronic equipment, and relates to the field of equipment authentication. The master device sends an authentication request to the slave device; wherein the authentication request is used for indicating the slave device to periodically generate authentication data through a fixed algorithm; obtaining to-be-authenticated data at a preset time point from the slave device; wherein the to-be-authenticated data is authentication data newly generated by the slave device at a preset time point; and if the to-be-authenticated data is different from the expected data at the preset time point, judging that the slave equipment does not pass the authentication. Therefore, a time factor is added in the equipment authentication process, so that the authentication process does not depend on static data and keys any more, and the cracking difficulty of an attacker is increased.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of device authentication, and more specifically, to an authentication method, device, storage medium and electronic device. Background Art

[0002] In some high-value protection scenarios (for example, Bluetooth accessories, printer toner cartridges, etc.), in order to prevent counterfeit and shoddy products from adversely affecting the original ecology, the terminal device (hereinafter referred to as the main device) often needs to authenticate its accessories (hereinafter referred to as the slave device). Only accessories that have passed the authentication can obtain terminal device authorization and perform their normal functions.

[0003] The master device and slave device mentioned above can be different devices in different application scenarios. For example, in the smart pairing scenario, the master device can be a smartphone, tablet or other smart terminal, and the slave device can be a wearable device such as a smart watch, health monitoring bracelet, smart headset, etc.; in the IoT scenario, the master device can be a gateway or central controller, and the slave device can be various sensors (such as temperature sensors, humidity sensors), smart home appliances (such as smart bulbs, smart sockets), etc. In the office scenario, the master device can be a printer, and the slave device can be a scanner, ink cartridge, powder box, etc.

[0004] like Figure 1 As shown, in the relevant authentication method, the slave device uses the key stored and calculated internally to operate the data sent by the master device with a fixed authentication algorithm, generates a unique operation result, and sends it to the master device. The master device then verifies the calculation result, and if the verification passes, the execution is successful.

[0005] After research, it was found that for the same data input and the same key, the calculation result of the authentication algorithm is always fixed. This makes the authentication process logic simple and lacks changes, so attackers can relatively easily simulate this authentication process and then imitate it. Summary of the invention

[0006] In order to overcome at least one of the deficiencies in the prior art, the present application provides an authentication method, device, storage medium and electronic device, specifically including:

[0007] In a first aspect, the present application provides an authentication method, applied to a master device communicating with a slave device, the method comprising:

[0008] Sending an authentication request to the slave device, wherein the authentication request is used to instruct the slave device to periodically generate authentication data through a fixed algorithm;

[0009] Obtaining data to be authenticated at a preset time point from the slave device, wherein the data to be authenticated is the authentication data most recently generated by the slave device at the preset time point;

[0010] If the data to be authenticated is different from the expected data at the preset time point, it is determined that the slave device has failed authentication.

[0011] In a second aspect, the present application provides an authentication method, which is applied to a slave device communicating with a slave master device, and the method includes:

[0012] Receiving an authentication request sent by the master device;

[0013] In response to the authentication request, periodically generating authentication data by a fixed algorithm;

[0014] The data to be authenticated at a preset time point is sent to the master device, wherein the data to be authenticated is the authentication data most recently generated by the slave device at the preset time point.

[0015] In a third aspect, the present application provides an authentication device, applied to a master device communicating with a slave device, the device comprising:

[0016] An authentication request module, used for sending an authentication request to the slave device, wherein the authentication request is used to instruct the slave device to periodically generate authentication data through a fixed algorithm;

[0017] An authentication determination module, used to obtain the data to be authenticated at a preset time point from the slave device, wherein the data to be authenticated is the authentication data most recently generated by the slave device at the preset time point;

[0018] The authentication determination module is further configured to determine that the slave device has not passed the authentication if the data to be authenticated is different from the expected data at the preset time point.

[0019] In a fourth aspect, the present application provides an authentication device, applied to a slave device communicating with a slave master device, the device comprising:

[0020] A request receiving module, used to receive an authentication request sent by the master device;

[0021] A request response module, used to periodically generate authentication data through a fixed algorithm in response to the authentication request;

[0022] The request response module is further configured to send the data to be authenticated at a preset time point to the master device, wherein the data to be authenticated is the authentication data most recently generated by the slave device at the preset time point.

[0023] In a fifth aspect, the present application provides a storage medium, wherein the storage medium stores a computer program, and the computer program implements the authentication method under the condition that it is executed by a processor.

[0024] In a sixth aspect, the present application provides an electronic device, comprising a processor and a memory, wherein the memory stores a computer program, and the computer program implements the authentication method under the condition that it is executed by the processor.

[0025] Compared with the prior art, this application has the following beneficial effects:

[0026] The present application provides an authentication method, apparatus, storage medium and electronic device. The master device sends an authentication request to the slave device; the authentication request is used to instruct the slave device to periodically generate authentication data through a fixed algorithm; the data to be authenticated at a preset time point is obtained from the slave device; the data to be authenticated is the latest authentication data generated by the slave device at the preset time point; if the data to be authenticated is different from the expected data at the preset time point, it is determined that the slave device has failed the authentication. In this way, the time factor is added to the device authentication process, so that the authentication process no longer relies on static data and keys, thereby increasing the difficulty of cracking by attackers. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0028] Figure 1 A schematic diagram of the principle of the existing authentication method provided in the embodiment of the present application;

[0029] Figure 2 One of the flowcharts of the authentication method provided in the embodiment of the present application;

[0030] Figure 3 A schematic diagram of a computing node provided in an embodiment of the present application;

[0031] Figure 4 A schematic diagram of the time rule provided for the embodiment of the present application;

[0032] Figure 5 The second flowchart of the authentication method provided in the embodiment of the present application;

[0033] Figure 6 One of the structural diagrams of the authentication device provided in the embodiment of the present application;

[0034] Figure 7 The second structural diagram of the authentication device provided in the embodiment of the present application;

[0035] Figure 8 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application;

[0036] Fig. 9 A circuit structure of a master device / slave device provided in an embodiment of the present application;

[0037] Fig.10 The current structure of the frequency modification module provided in the embodiment of the present application;

[0038] Fig.11 The circuit structure of the authentication algorithm module provided in the embodiment of the present application. DETAILED DESCRIPTION

[0039] In order to make the purpose, technical solution and advantages of the embodiments of the present application clearer, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. The components of the embodiments of the present application described and shown in the drawings here can be arranged and designed in various different configurations.

[0040] Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the present application for which protection is sought, but merely represents selected embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in the field without creative work are within the scope of protection of the present application.

[0041] It should be noted that similar reference numerals and letters denote similar items in the following drawings, and therefore, once an item is defined in one drawing, further definition and explanation thereof is not required in subsequent drawings.

[0042] In the description of the present application, it should be noted that the terms "first", "second", "third", etc. are only used to distinguish the description and cannot be understood as indicating or implying relative importance. In addition, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or device including the element.

[0043] Based on the above statement, as introduced in the background technology, for the same data input and the same key, the calculation result of the authentication algorithm is always fixed. This makes the authentication process logic simple and lacks changes, so attackers can relatively easily simulate this authentication process and then imitate it.

[0044] Exemplarily, the master device generates a random number and sends it to the slave device. Then, after receiving the random number sent by the master device, the slave device uses the session key and the random number to perform calculations to generate calculation results, and feeds the calculation results back to the master device. After receiving the data fed back by the slave device, the master device starts to authenticate it; if the authentication is successful, the master device will perform subsequent functions normally; if the authentication fails, the master device will report an error.

[0045] Therefore, for the same data input and the same key, the calculation result of the authentication algorithm is always fixed. This makes the authentication process logic simple and lacks variation, so attackers can simulate this authentication process relatively easily.

[0046] For example, an attacker can collect enough data samples, including fixed data sent by the main device and the corresponding encryption results. This data can be obtained from genuine accessories already available on the market, or extracted from existing products through reverse engineering. Then, the attacker uses these data samples for reverse engineering to try to understand the specific implementation of the authentication algorithm. This may involve a detailed analysis of the hardware and software of the existing accessories to determine the encryption algorithm, key management method, and other relevant parameters used internally. Then, the attacker can write a simulation program that can simulate the behavior of the existing accessories. After debugging, it is ensured that it can pass the authentication of the main device under various circumstances, thereby completing the imitation.

[0047] Based on the discovery of the above technical problems, the inventors have proposed the following technical solutions to solve or improve the above problems through creative work. It should be noted that the defects in the solutions in the above prior art are the results obtained by the inventors after practice and careful research. Therefore, the discovery process of the above problems and the solutions proposed in the embodiments of the present application for the above problems below should all be the contributions made by the inventors to the present application in the process of invention and creation, and should not be understood as technical contents known to those skilled in the art.

[0048] In order to prevent rapid imitation, the embodiment of the present application (hereinafter referred to as the present embodiment) proposes a new authentication method. This method adds a time factor to the authentication process, so that the authentication process no longer relies on static data and keys, thereby increasing the difficulty of cracking by attackers. Figure 2 As shown, the method includes:

[0049] S1A, sends an authentication request to the slave device.

[0050] The authentication request is used to instruct the slave device to periodically generate authentication data using a fixed algorithm.

[0051] S2A, obtains the data to be authenticated at a preset time point from the slave device.

[0052] The data to be authenticated is the authentication data newly generated by the slave device at a preset time point.

[0053] S3A: If the data to be authenticated is different from the expected data at the preset time point, it is determined that the slave device has failed the authentication.

[0054] In this way, the time factor is added to the device authentication process, so that the authentication process no longer relies on static data and keys, thereby increasing the difficulty for attackers to crack.

[0055] To make the solution provided by this embodiment clearer, the printer is used as the master device and the ink cartridge is used as the slave device. Figure 2 However, it should be understood that the operations of the flowchart may not be implemented in order, and steps without logical contextual relationships may be reversed or implemented simultaneously. In addition, those skilled in the art may add one or more other operations to the flowchart, or remove one or more operations from the flowchart, under the guidance of the content of this application. Figure 2 , the method comprising:

[0056] S1A, sends an authentication request to the slave device.

[0057] The authentication request is used to instruct the slave device to periodically generate authentication data using a fixed algorithm.

[0058] In this embodiment, due to the use of a fixed algorithm, the time taken by the ink cartridge to calculate the authentication data each time is the same, thereby ensuring the predictability of the authentication process. It can be understood that since the time taken by the ink cartridge to calculate the authentication data each time is the same, the printer can predict the theoretical expected data at each preset time point, so as to more accurately determine whether the ink cartridge has completed the authentication calculation on time. If the ink cartridge fails to return the expected authentication data within the predetermined time, the printer can promptly detect the abnormality and take corresponding measures, thereby improving the reliability and security of the entire authentication process.

[0059] In this embodiment, the operation cycle of the above-mentioned fixed algorithm can be a time cycle preset for the ink cartridge. Specifically, the time cycle can be defined as a certain number of clock signals, for example, every 1000 clock signals is a cycle. In this cycle, the ink cartridge will run the fixed algorithm to generate an authentication data of the cycle. Then, in the next time cycle, the ink cartridge will generate a new authentication data. In this way, the dynamic change of the authentication data is ensured. Since the data generated each time is different, the difficulty of imitation is increased.

[0060] In addition, since the algorithm is fixed, it means that the algorithm runs for the same time, so the cycle can also be the running time of the fixed algorithm. It can be understood that no matter when the algorithm is started, a complete running cycle will be completed in the same time. For example, the algorithm may take 1 second to generate an authentication data. In this case, the ink cartridge will generate an authentication data every 1 second. Therefore, the ink cartridge will generate an authentication data at each fixed time interval. In this embodiment, the end time of each cycle is called an algorithm node, which means that an authentication data will be generated at this algorithm node.

[0061] In this embodiment, the authentication data generated in each cycle is different, so that the authentication data has the characteristic of dynamic change. In this regard, the ink cartridge can change the input data of the algorithm in each cycle, so that the authentication data generated in each cycle is different. For example, the ink cartridge can input the initial data into a fixed algorithm to generate an authentication data; then, the generated authentication data continues to be input into the fixed algorithm in the next cycle to obtain new authentication data. This cycle repeats, because the input data changes with each algorithm run, the data generated each time will be different. This mechanism ensures that even if the algorithm itself is fixed, the generated data will continue to change dynamically to facilitate the printer to perform authentication and identification.

[0062] For another example, the ink cartridge can input initial data into a fixed algorithm to generate an authentication data; then, in the next cycle, the initial data is added to the current cycle number and then input into the fixed algorithm again to obtain new authentication data. This cycle repeats itself, because the input data changes with each algorithm run, so the data generated each time will also be different. This mechanism ensures that even if the algorithm itself is fixed, the generated data will continue to change dynamically to facilitate authentication and identification by the printer.

[0063] The above initial data can be data agreed upon in advance between the ink cartridge and the printer, or can be generated by the printer and sent to the ink cartridge during each authentication process. Therefore, the authentication request sent by the printer can include the initial data generated by the master device; the initial data is used to instruct the slave device to periodically generate dynamically changing authentication data based on the initial data through a fixed algorithm. The initial data can be a random number generated by the printer through a random algorithm.

[0064] Based on the description of the authentication request in the above embodiment, Figure 2 Step S2A in the following example is described as follows:

[0065] S2A, obtains the data to be authenticated at a preset time point from the slave device.

[0066] The data to be authenticated is the authentication data newly generated by the slave device at a preset time point.

[0067] In this embodiment, if the ink cartridge cannot actively send data to the printer, the printer can send a data acquisition request to the slave device when a preset time point is reached, wherein the data acquisition request is used to instruct the slave device to send the authentication data most recently generated at the preset time point as the data to be authenticated to the master device; thereby receiving the data to be authenticated sent by the slave device.

[0068] Of course, for a scenario where the slave device can actively send data to the master device, the slave device can also send the authentication data most recently generated at a preset time point as data to be authenticated to the master device at each specific time point.

[0069] For example, Figure 3 The multiple algorithm nodes (node ​​1 to node N) shown in the figure generate an authentication data at each algorithm node. When the preset time point is between node 1 and node 2, the authentication data generated by node 1 is the latest authentication data generated by the ink cartridge at this time, so the authentication data generated by node 1 is sent to the printer as the data to be authenticated. Similarly, when the preset time point is between node 2 and node 3, the authentication data generated by node 2 is the latest authentication data generated by the ink cartridge at this time, so the authentication data generated by node 2 is sent to the printer as the data to be authenticated.

[0070] Based on the description of the above embodiment for treating authentication data, the following will continue Figure 2 Step S3A in the following example is described as follows:

[0071] S3A: If the data to be authenticated is different from the expected data at the preset time point, it is determined that the slave device has failed the authentication.

[0072] It can be understood that during the authentication process, the printer already knows the performance of the original processor used by the ink cartridge and is aware of the algorithm used for the authentication data. In this case, the printer can accurately predict the authentication data that the ink cartridge should calculate at a preset time point based on the operation process of the algorithm and the device performance of the ink cartridge. For example, the printer can adjust its own device performance to be consistent with the ink cartridge, and run the same algorithm for calculation to obtain the expected data at a preset time point. Or the printer records the expected data of the ink cartridge at a preset time point in advance.

[0073] Since the authentication data at different nodes has the characteristics of dynamic change, the printer can compare the received data to be authenticated with the expected data. If the received data to be authenticated is consistent with the expected data expected by the printer, it means that the ink cartridge uses the original processor and the algorithm execution process is as expected, and the authentication is judged to be successful. However, if the received data to be authenticated does not match the expected data, that is, the data sent by the ink cartridge does not meet the printer's predicted results, this indicates that the ink cartridge may use a non-original processor, or there is an abnormality in the algorithm execution process, so the printer determines that the slave device has not passed the authentication.

[0074] In this way, by predicting and comparing the authentication data, it is possible to detect whether the ink cartridge uses an original processor, thereby completing the authentication of the ink cartridge.

[0075] In addition, the number of preset time nodes in this embodiment can be multiple, and the printer can verify the ink cartridge multiple times at different time nodes. As long as the data to be authenticated at one time node is inconsistent with the expected data, the ink cartridge is determined to have failed the authentication.

[0076] In this embodiment, in order to further increase the difficulty of cracking the device authentication process, the speed of generating authentication data can also be controlled by adjusting the device performance of the ink cartridge. Specifically, the speed at which the algorithm runs in the ink cartridge can be changed to make the authentication data generation process unpredictable, thereby increasing the difficulty of cracking.

[0077] Therefore, in Figure 2 Before step S1A, the printer may also send a speed adjustment request to the ink cartridge, wherein the speed adjustment request includes a performance adjustment parameter, and the performance adjustment parameter is used to instruct the ink cartridge to adjust the speed of generating authentication data.

[0078] In this embodiment, in order to prevent the performance adjustment parameter from being tampered with during transmission, the verification reference value is used to instruct the slave device to perform a verification operation on the performance adjustment parameter to obtain a verification operation value; and to determine whether the verification operation value is consistent with the verification reference value.

[0079] Exemplarily, before sending the performance adjustment parameters, the printer will perform some form of verification operation (such as hash operation, checksum calculation, etc.) on these parameters to generate a verification reference value. The verification reference value contains summary information of the performance adjustment parameters and can reflect the content and structural characteristics of the parameters. When the ink cartridge receives the performance adjustment parameters, it will use the same verification algorithm to recalculate these parameters to obtain a new verification operation value; then, the two are compared. If the two are consistent, it means that the performance adjustment parameters have not been tampered with during the transmission process. At this time, the ink cartridge can feedback a success mark or an end mark to the printer or not feedback, and adjust its own device performance according to the performance adjustment parameters. On the contrary, if the two are inconsistent, it means that the parameters may have been tampered with during the transmission process, and the ink cartridge will refuse to accept these parameters and feedback an error mark or an end mark to the printer.

[0080] The performance adjustment parameter may be the frequency adjustment information of the ink cartridge. Since the frequency adjustment information of the ink cartridge involves the operating frequency of the processor, that is, the number of instruction cycles that the processor can complete per second, the speed at which the algorithm is executed in the ink cartridge can be significantly affected by adjusting the operating frequency of the processor. For example, if the operating frequency of the processor is high, more instructions can be processed per unit time, thereby speeding up the generation of authentication data. On the contrary, if the operating frequency is low, the speed at which the processor processes instructions slows down, and the generation speed of authentication data will also decrease accordingly.

[0081] For example, Figure 4 As shown in the figure, the ink cartridge can be set to a low-frequency clock, a medium-frequency clock, or a high-frequency clock through different frequency adjustment information. Under different clock frequencies, the ink cartridge will generate authentication data at different rates. It is not difficult to see that the higher the clock frequency, the smaller the time interval between algorithm nodes, which means that the authentication data is calculated faster.

[0082] Therefore, in this embodiment, by controlling the clock frequency of the ink cartridge, even if the attacker cracks the performance adjustment process of the ink cartridge and tries to imitate this process to produce a counterfeit product. Since the clock generator of the original product is strictly designed and tested, it can be ensured that it can work stably under various environmental conditions. However, due to the different manufacturing processes, it is difficult for counterfeit products to completely replicate the clock generator characteristics of the original product. For example, even a small manufacturing error may cause a deviation in the frequency output of the counterfeit clock generator. This means that even if the counterfeit product is configured with the same frequency adjustment information, it cannot achieve the same frequency adjustment effect as the original product. Therefore, this deviation will cause the counterfeit product to be unable to accurately restore the frequency adjustment effect of the original chip, thereby affecting the speed of generating authentication data.

[0083] In this way, by adjusting the performance of the ink cartridge device, even if the attacker knows the specific details of the algorithm and the device performance parameters of the ink cartridge, he cannot accurately predict what kind of authentication data the ink cartridge should generate at a certain point in time. This also means that the performance adjustment of the ink cartridge leads to changes in the speed of authentication data generation, making the data generated each time more random and uncertain. In addition, the difference in chip manufacturing process provides additional protection for the original product, making it impossible for the imitation product to be completely equivalent to the original product in terms of function, further improving the overall security of the system.

[0084] In addition, the above performance adjustment parameters, in addition to the above frequency adjustment information, may also be memory access speed or other hardware parameters or software parameters that can affect the speed of algorithm operation.

[0085] In the above embodiment, the authentication method is described from the perspective of the printer. Based on the same inventive concept, the following describes the authentication method implemented by the ink cartridge as a slave device. Figure 5 As shown, the method includes:

[0086] S1B, receives the authentication request sent by the master device.

[0087] S2B, in response to the authentication request, periodically generates authentication data using a fixed algorithm.

[0088] S3B, sending the data to be authenticated at the preset time point to the main device.

[0089] The data to be authenticated is the authentication data newly generated by the slave device at a preset time point. In this embodiment, if the ink cartridge does not support actively sending data to the printer, the ink cartridge can accept the data acquisition request sent by the printer at the preset time point and send the data to be authenticated to the master device. If the ink cartridge supports actively sending data to the printer, the data to be authenticated can be actively sent to the printer when the preset time point is reached.

[0090] In addition, in this embodiment, in order to ensure that the authentication data is in a dynamically changing state, the cartridge can change the data input to the algorithm in each cycle. For example, the cartridge can input the initial data into a fixed algorithm to generate a piece of authentication data. Then, in the next cycle, the cartridge inputs the generated authentication data into the same fixed algorithm again to generate new authentication data. This mechanism ensures the continuous dynamic change of the authentication data by continuously using the data generated last time as new input, so that the data generated each time is different.

[0091] In addition, the cartridge can also use another method to ensure that the authentication data changes. In each cycle, the cartridge can input the initial data into a fixed algorithm to generate a piece of authentication data. Then, in the next cycle, the cartridge adds the initial data to the current cycle number and continues to input it into the fixed algorithm to generate new authentication data. In this way, each input data will change due to the increase in the cycle number, thereby ensuring that the generated data is different each time.

[0092] The above initial data can be data agreed upon in advance between the ink cartridge and the printer, or can be generated by the printer and sent to the ink cartridge through an authentication request during each authentication process. The authentication request sent by the printer contains the initial data generated by the printer, which is used to instruct the ink cartridge to periodically generate dynamically changing authentication data based on the initial data through a fixed algorithm. For example, the initial data can be a random number generated by the printer to further increase the unpredictability of data changes.

[0093] In addition, in order to further increase the difficulty of cracking the device authentication process, the printer can also control the speed of generating authentication data by adjusting the device performance of the ink cartridge. Figure 5 Before step S1B shown, the ink cartridge may also receive a speed adjustment request sent by the host device, wherein the speed adjustment request includes a performance adjustment parameter; in response to the speed adjustment request, the speed of generating the authentication data is adjusted according to the performance adjustment parameter.

[0094] Since the speed of generating authentication data is controlled by the clock of the slave device, the performance adjustment parameter is the frequency adjustment information. It can be understood that the frequency adjustment information can be used to change the frequency of the clock to make the processor work faster or slower. If the frequency adjustment information increases the clock frequency, the processor can process more instructions per second, thereby speeding up the generation of authentication data. Conversely, if the frequency adjustment information reduces the clock frequency, the speed at which the processor processes instructions slows down, and the generation speed of authentication data will also decrease accordingly.

[0095] In this way, the printer can control the time interval for the ink cartridge to generate authentication data by changing the clock frequency, which increases the difficulty for attackers to predict and imitate the generation process. Even if attackers can master the logic of the algorithm itself, due to differences in manufacturing processes, it will be difficult for counterfeit products to quickly design a clock generator that is exactly the same as the original product, making it difficult for counterfeit products to complete authentication.

[0096] Based on the same inventive concept as the authentication method provided in this embodiment, this embodiment also provides an authentication device for a master device that communicates with a slave device, the device comprising at least one software function module that can be stored in a memory in the form of software. The processor in the master device is used to execute the executable module stored in the memory. For example, the software function module and computer program included in the device. Please refer to Figure 6 , functionally speaking, the device may include:

[0097] The authentication request module 11A is used to send an authentication request to the slave device, wherein the authentication request is used to instruct the slave device to periodically generate authentication data through a fixed algorithm.

[0098] The authentication determination module 12A is used to obtain the data to be authenticated at a preset time point from the slave device, wherein the data to be authenticated is the authentication data newly generated by the slave device at the preset time point.

[0099] The authentication determination module 12A is further configured to determine that the slave device has not passed the authentication if the data to be authenticated is different from the expected data at a preset time point.

[0100] In this embodiment, the authentication request module 11A is used to implement Figure 2 In step S1A, the authentication and determination module 12A is used to implement Figure 2 Therefore, for the detailed description of the above modules, please refer to the specific implementation methods of the corresponding steps.

[0101] In addition, since the authentication method for a master device communicating with a slave device has the same inventive concept, the authentication device can also implement other steps or sub-steps of the method through the above modules.

[0102] Optionally, before the authentication request module 11A sends the authentication request to the slave device, the authentication request module 11A is further configured to:

[0103] A speed adjustment request is sent to the slave device, wherein the speed adjustment request includes a performance adjustment parameter, and the performance adjustment parameter is used to instruct the slave device to adjust a speed of generating authentication data.

[0104] Optionally, the authentication and determination module 12A is further specifically used for:

[0105] When the preset time point is reached, a data acquisition request is sent to the slave device, wherein the data acquisition request is used to instruct the slave device to send the authentication data most recently generated at the preset time point as the data to be authenticated to the master device;

[0106] Receive the data to be authenticated sent by the slave device.

[0107] Based on the same inventive concept as the authentication method provided in this embodiment, this embodiment also provides an authentication device for a slave device communicating with a master device, the device comprising at least one software function module that can be stored in a memory in the form of software. The processor in the slave device is used to execute the executable module stored in the memory. For example, the software function module and computer program included in the device. Please refer to Figure 7 , functionally speaking, the device may include:

[0108] The request receiving module 11B is used to receive the authentication request sent by the master device;

[0109] The request response module 12B is used to periodically generate authentication data by a fixed algorithm in response to the authentication request;

[0110] The request response module 12B is further used to send the data to be authenticated at a preset time point to the master device, wherein the data to be authenticated is the authentication data newly generated by the slave device at the preset time point.

[0111] In this embodiment, the request receiving module 11B is used to implement Figure 5 In S1B, the request response module 12B is used to implement Figure 5 Therefore, for the detailed description of the above modules, please refer to the specific implementation of the corresponding steps.

[0112] In addition, since the authentication method has the same inventive concept as that applied to the authentication method of the slave device communicating with the master device, the authentication device can also implement other steps or sub-steps of the method through the above modules.

[0113] Optionally, the request receiving module 11B is further used for:

[0114] A speed adjustment request sent by a master device is received, wherein the speed adjustment request includes a performance adjustment parameter.

[0115] The request response module 12B is also used for:

[0116] In response to the speed adjustment request, the speed of generating the authentication data is adjusted according to the performance adjustment parameter.

[0117] Optionally, the speed of generating the authentication data is controlled by the clock of the slave device, the performance adjustment parameter is the frequency adjustment information, and the request response module 12B is further specifically used for:

[0118] The clock frequency of the clock is adjusted according to the frequency adjustment information.

[0119] In addition, the functional modules in the various embodiments of the present application may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.

[0120] It should also be understood that if the above implementation is implemented in the form of a software function module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application.

[0121] Therefore, this embodiment also provides a storage medium, which is a computer-readable storage medium. The storage medium stores a computer program, and when the computer program is executed by the processor, the authentication method provided in this embodiment is implemented, and the method can be applied to a master device communicating with a slave device or to a slave device communicating with a master device. Among them, the storage medium can be a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a disk or an optical disk, etc., which can store program codes.

[0122] This embodiment provides an electronic device for implementing the above authentication method. Figure 8 As shown, the electronic device may include a processor 22 and a memory 21. In addition, the memory 21 stores a computer program, and the processor implements the authentication method provided in this embodiment by reading and executing the computer program corresponding to the above implementation in the memory 21. The method can be applied to a master device communicating with a slave device or to a slave device communicating with a master device.

[0123] Continue to see Figure 8 The electronic device further includes a communication unit 23. The memory 21, the processor 22 and the communication unit 23 are electrically connected to each other directly or indirectly through a system bus 24 to achieve data transmission or interaction.

[0124] The memory 21 may be an information recording device based on any electronic, magnetic, optical or other physical principle, used to record execution instructions, data, etc. In some embodiments, the memory 21 may be, but is not limited to, a volatile memory, a non-volatile memory, a storage drive, etc.

[0125] In some embodiments, the volatile memory may be a random access memory (RAM); in some embodiments, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable read-only memory (EEPROM), a flash memory, etc.; in some embodiments, the storage drive may be a disk drive, a solid-state drive, any type of storage disk (such as a CD, a DVD, etc.), or a similar storage medium, or a combination thereof, etc.

[0126] The communication unit 23 is used to send and receive data through a network. In some embodiments, the network may include a wired network, a wireless network, a fiber optic network, a telecommunication network, an intranet, the Internet, a local area network (LAN), a wide area network (WAN), a wireless local area network (WLAN), a metropolitan area network (MAN), a wide area network (WAN), a public switched telephone network (PSTN), a Bluetooth network, a ZigBee network, or a near field communication (NFC) network, or any combination thereof. In some embodiments, the network may include one or more network access points. For example, the network may include a wired or wireless network access point, such as a base station and / or a network switching node, through which one or more components of the service request processing system may be connected to the network to exchange data and / or information.

[0127] The processor 22 may be an integrated circuit chip having a signal processing capability, and the processor may include one or more processing cores (e.g., a single-core processor or a multi-core processor). By way of example only, the processor may include a central processing unit (CPU), an application specific integrated circuit (ASIC), an application specific instruction set processor (ASIP), a graphics processing unit (GPU), a physical processing unit (PPU), a digital signal processor (DSP), a field programmable gate array (FPGA), a programmable logic device (PLD), a controller, a microcontroller unit, a reduced instruction set computer (RISC), or a microprocessor, or any combination thereof.

[0128] Understandably, Figure 8 The structure shown is for illustration only. The electronic device may also have Figure 8 More or fewer components than shown, or with Figure 8 Different configurations are shown. It is worth noting that Figure 8 The components shown can be implemented by hardware, software or a combination thereof. That is, the implementation of the processing flow in the above embodiments is not limited to the processor reading and running pure computer-readable program code from the memory, but can also be implemented by hardware or logic devices.

[0129] It should also be understood that improvements to a technology can be divided into hardware improvements (for example, improvements to circuit structures such as diodes, transistors, switches, etc.) and software improvements (improvements to method flows). However, with the development of technology, many improvements to method flows today can be regarded as direct improvements to hardware circuit structures. Designers almost always obtain the corresponding hardware circuit structure by programming the improved method flow into the hardware circuit. Therefore, it cannot be said that an improvement to a method flow cannot be implemented using a hardware entity module. For example, a programmable logic device (PLD) (such as a field programmable gate array (FPGA)) is such an integrated circuit whose logical function is determined by the user's programming of the device. Designers can "integrate" a digital system on a PLD by programming it themselves, without having to ask a chip manufacturer to design and make a dedicated integrated circuit chip. Moreover, nowadays, instead of manually making integrated circuit chips, this kind of programming is mostly implemented by "logic compiler" software, which is similar to the software compiler used when developing and writing programs. The original code before compilation must also be written in a specific programming language, which is called hardware description language (HDL). There is not only one kind of HDL, but many kinds, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. Among them, VHDL (Very High Speed ​​Integrated Circuit Hardware Description Language) and Verilog are the most commonly used.

[0130] Therefore, those skilled in the art should also be aware that they only need to perform some logic programming on the method flow using the above-mentioned hardware description languages ​​and program it into an integrated circuit to easily obtain a hardware circuit that implements the logical method flow.

[0131] like Fig. 9As shown, from the perspective of circuit implementation, the master device or slave device in this embodiment may include a communication module 31, an authentication algorithm module 33, and a frequency modification module 32. The communication module 31 may be configured as a common integrated circuit bus (Inter-Integrated Circuit, IIC) transceiver, a serial peripheral interface (Serial Peripheral Interface, SPI) transceiver, etc., and its communication instruction format may be defined as:

[0132] First instruction: The master device sends performance adjustment parameters and verification reference values ​​based on these parameters. After receiving the slave device, it will feedback a response result including a success mark or a failure mark.

[0133] Second instruction: The master device sends authentication data and requests the slave device to feedback data at a specific time. After receiving the request, the slave device will feedback the data to be authenticated.

[0134] The following takes the slave device as an example to further describe the frequency modification module 32. Fig.10 As shown, Fig. 9 The frequency modification module 32 in the embodiment includes a verification algorithm circuit 321, a comparator 323, a clock generator 322 and a clock selector 324. The frequency modification module 32 works as follows:

[0135] (1) The clock generator 322 includes multiple clock signals with different frequencies. These clock signals can be selected and switched by the clock generator 322 according to the frequency adjustment information.

[0136] (2) The verification algorithm circuit 321 is used to receive the frequency adjustment information, calculate the algorithm result and send it to the comparator 323;

[0137] (3) The comparator 323 is responsible for comparing the result calculated by the verification algorithm circuit 321 with a preset verification reference value. If the calculation result is consistent with the verification reference value, the comparator 323 outputs success flag information; if not, it outputs failure flag information.

[0138] (4) The clock selector 324 selects an output clock signal from the multiple clock signals according to the output of the comparator 323 (i.e., the valid flag) and the frequency adjustment information. If the frequency adjustment information is valid, the clock selector 324 selects an appropriate clock frequency for output; otherwise, it outputs a default clock signal.

[0139] The verification algorithm can be defined as a standard security algorithm or a custom algorithm, and the key can be set as a fixed value / memory storage data or more instructions can be added before the first instruction to interact / generate the key. The clock generator 322 can be designed as a single clock with a frequency adjustment function, and the frequency adjustment information is used as the input of the clock generator 322, and the valid flag output by the comparator 323 is directly used as the valid flag of the frequency adjustment information.

[0140] like Fig.11 As shown, Fig. 9 The authentication algorithm module 33 in the embodiment includes a node controller 331, an authentication algorithm circuit 332 and an algorithm result register 333. The authentication algorithm module 33 works as follows:

[0141] (1) Before the algorithm is started, the node controller 331 will send a reset signal to reset the algorithm result register 333 to an initial value or a fixed value. This is done to ensure that the algorithm is in a known initial state at the beginning, avoiding the uncertainty caused by the previous state affecting the authentication process.

[0142] (2) The node controller 331 generates an algorithm start flag and sends it to the authentication algorithm circuit 332. This marks the formal start of the algorithm execution. At this point, the authentication algorithm circuit 332 is ready to accept input data and start processing.

[0143] (3) The authentication algorithm circuit 332 starts working. The input data can be the initial data sent by the master device or the result of the previous node calculation. When the algorithm executes to a certain node, the authentication algorithm circuit 332 will send a node completion flag to the node controller 331. The node controller 331 will receive this flag and prepare to process the next operation.

[0144] (4) The node controller 331 generates an enable signal and a clock signal. The enable signal is used to activate the algorithm circuit to perform the next step of calculation, while the clock signal is used to synchronize the execution of the algorithm to ensure that each step is performed at a predetermined time interval.

[0145] (5) The algorithm result register 333 reads data from the authentication algorithm circuit 332 and stores the data as the data to be authenticated at the current time node. In this way, each time the algorithm executes to a node, the latest authentication data will be saved for subsequent comparison and verification.

[0146] (6) Repeat steps (3) to (5) at other time points. This ensures that the authentication algorithm can continuously generate and store the latest authentication data during the entire authentication process until the algorithm is executed.

[0147] (7) When the authentication algorithm reaches the end point, the authentication algorithm circuit 332 sends a completion flag to the node controller 331. After receiving the completion flag, the node controller 331 generates a new enable signal and clock signal to update the value of the algorithm result register 333. At the same time, the node controller 331 enters the time overflow point and generates a reset signal again to reset the algorithm result register 333 to the initial value or fixed value to prepare for the next round of algorithm execution.

[0148] After receiving the completion mark for a period of time, the node controller 331 enters a time overflow point and generates a reset signal to reset the algorithm result register 333 to an initial value / fixed value.

[0149] In addition, when the node controller 331 receives the feedback flag information, the control signal generated by it will stop the authentication algorithm. At the same time, the enable signal and clock signal generated by the node controller 331 will update the value of the algorithm result register 333. These updated data will be passed to the communication module for further reading and output. In this way, the authentication algorithm module can ensure that the latest authentication data generated during the algorithm execution process can be accurately stored and transmitted for subsequent verification.

[0150] It should be understood that the selection of authentication algorithms and their nodes is flexible. It can be a split or repetition of a standard algorithm, or a self-defined split of a single algorithm or a superposition of multiple algorithms. This flexibility allows the system to be customized according to specific application scenarios and requirements, thereby improving the accuracy and security of authentication.

[0151] In this way, by introducing the time factor into the authentication process, the output of the authentication algorithm is no longer fixed, but depends on the specific time point and the length of time the algorithm is executed. Even with the same input data and key, the result of each authentication will be different. This variability greatly increases the difficulty of imitation, because attackers cannot replicate the authentication process through simple data collection and reverse engineering.

[0152] Secondly, the cooperation between the frequency modification module 32 and the authentication algorithm module 33 further enhances the security of authentication. The frequency modification module 32 can select the appropriate clock signal according to the received frequency adjustment information to ensure that the algorithm can run at different frequencies. The change of frequency increases the difficulty of copying by counterfeiters, because even if the attackers have mastered the specific details of the algorithm, it is difficult for them to accurately simulate the algorithm execution process at different frequencies.

[0153] The authentication algorithm module 33 manages and controls the execution process of the algorithm through the node controller 331. The node controller 331 ensures that the calculation results of each node can be accurately recorded and verified. In addition, the node controller 331 can also generate corresponding flag information according to the different stages of the algorithm to ensure that the algorithm is fed back and reset at the right time. For example, when the algorithm reaches a certain key node, the node controller 331 will generate a node completion flag to notify the algorithm module to proceed to the next step. This sophisticated control and management mechanism ensures the reliability and consistency of the entire authentication process.

[0154] It should be understood that the apparatus and method disclosed in the above-mentioned embodiments can also be implemented in other ways. The apparatus embodiments described above are merely schematic. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architecture, functions and operations of the apparatus, methods and computer program products according to the multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of a code, and the module, a program segment or a part of a code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or the flowchart, and the combination of boxes in the block diagram and / or the flowchart can be implemented with a dedicated hardware-based system that performs a specified function or action, or can be implemented with a combination of dedicated hardware and computer instructions.

[0155] The above are only various implementations of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

Claims

1. An authentication method, characterized in that: Applied to a master device communicating with a slave device, the method comprises: Sending an authentication request to the slave device, wherein the authentication request is used to instruct the slave device to periodically generate authentication data through a fixed algorithm; Obtaining data to be authenticated at a preset time point from the slave device, wherein the data to be authenticated is the authentication data most recently generated by the slave device at the preset time point; If the data to be authenticated is different from the expected data at the preset time point, it is determined that the slave device has failed authentication.

2. The authentication method according to claim 1, characterized in that: Before sending the authentication request to the slave device, the method further includes: A speed adjustment request is sent to the slave device, wherein the speed adjustment request includes a performance adjustment parameter, and the performance adjustment parameter is used to instruct the slave device to adjust a speed of generating the authentication data.

3. The authentication method according to claim 2, characterized in that: The speed adjustment request also includes a verification reference value; The verification reference value is used to instruct the slave device to perform a verification operation on the performance adjustment parameter to obtain a verification operation value; and to determine whether the verification operation value is consistent with the verification reference value.

4. The authentication method according to claim 1, characterized in that: The authentication request includes initial data generated by the master device; The initial data is used to instruct the slave device to periodically generate authentication data through a fixed algorithm based on the initial data.

5. The authentication method according to claim 1 or 4, characterized in that: The authentication data generated in each cycle is different.

6. The authentication method according to claim 1, characterized in that: Obtaining the data to be authenticated at a preset time point from the slave device includes: When the preset time point is reached, a data acquisition request is sent to the slave device, wherein the data acquisition request is used to instruct the slave device to send the authentication data most recently generated at the preset time point as the data to be authenticated to the master device; Receive the data to be authenticated sent by the slave device.

7. An authentication method, characterized in that: Applied to a slave device communicating with a slave master device, the method comprises: Receiving an authentication request sent by the master device; In response to the authentication request, periodically generating authentication data by a fixed algorithm; The data to be authenticated at a preset time point is sent to the master device, wherein the data to be authenticated is the authentication data most recently generated by the slave device at the preset time point.

8. The authentication method according to claim 7, characterized in that: The authentication request includes initial data generated by the master device, and authentication data is periodically generated by a fixed algorithm, including: Based on the initial data, authentication data is periodically generated by a fixed algorithm.

9. The authentication method according to claim 7 or 8, characterized in that: The authentication data generated in each cycle is different.

10. The authentication method according to claim 7, characterized in that: Before receiving the authentication request sent by the master device, the method further includes: receiving a speed adjustment request sent by the master device, wherein the speed adjustment request includes a performance adjustment parameter; In response to the speed adjustment request, the speed of generating the authentication data is adjusted according to the performance adjustment parameter.

11. The authentication method according to claim 10, characterized in that: The speed of generating the authentication data is controlled by the clock of the slave device, the performance adjustment parameter is frequency adjustment information, and the speed of generating the authentication data is adjusted according to the performance adjustment parameter, including: The clock frequency of the clock is adjusted according to the frequency adjustment information.

12. An authentication device, characterized in that: A master device for communicating with a slave device, the device comprising: An authentication request module, used for sending an authentication request to the slave device, wherein the authentication request is used to instruct the slave device to periodically generate authentication data through a fixed algorithm; An authentication determination module, used for obtaining data to be authenticated at a preset time point from the slave device, wherein the data to be authenticated is the authentication data most recently generated by the slave device at the preset time point; The authentication determination module is further configured to determine that the slave device has not passed the authentication if the data to be authenticated is different from the expected data at the preset time point.

13. An authentication device, characterized in that: A slave device for communicating with a slave master device, the device comprising: A request receiving module, used to receive an authentication request sent by the master device; A request response module, used to periodically generate authentication data through a fixed algorithm in response to the authentication request; The request response module is further used to send the data to be authenticated at a preset time point to the master device, wherein the data to be authenticated is the authentication data most recently generated by the slave device at the preset time point.

14. A storage medium, characterized in that: The storage medium stores a computer program, and the computer program, when executed by a processor, implements the authentication method described in any one of claims 1-6 or 7-11.

15. An electronic device, characterized in that: The electronic device includes a processor and a memory, the memory stores a computer program, and the computer program, when executed by the processor, implements the authentication method described in any one of claims 1-6 or 7-11.

Citation Information

Patent Citations

  • Method, Device, And System For Managing User Authentication

    CN104025505A

  • Authentication method and authentication system

    CN112788033A

  • Certificate generation method and system, electronic equipment and storage medium

    CN114282506A

  • Authentication method and device, electronic equipment and storage medium

    CN118199993A

  • Identity authentication method, device and equipment

    CN119299102A