Authentication method and device, storage medium and electronic device
By introducing a time factor into the authentication process, authentication data is generated periodically by the device and sent at preset time points, solving the problem of easy counterfeiting caused by fixed authentication algorithms in existing technologies, and improving the security and reliability of authentication.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- GUANGZHOU ZHONO ELECTRONICS TECH CO LTD
- Filing Date
- 2025-03-14
- Publication Date
- 2026-05-29
AI Technical Summary
In the existing authentication process, the results of the authentication algorithm are fixed, making it easy for attackers to simulate and imitate, resulting in a lack of variability and security in the authentication process.
The authentication process incorporates a time factor, enabling slave devices to periodically generate authentication data using a fixed algorithm and send the latest authentication data at preset time points. The master device then makes an authentication determination by comparing the data with the expected data.
This increases the difficulty for attackers to crack the authentication process and improves its reliability and security.
Smart Images

Figure CN119996054B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of device certification, and more specifically, to a certification method, apparatus, storage medium, and electronic device. Background Technology
[0002] In certain high-value protection scenarios (e.g., Bluetooth accessories, printer toner cartridges, etc.), in order to prevent counterfeit and substandard products from adversely affecting the original ecosystem, terminal devices (hereinafter referred to as master devices) often need to authenticate their accessories (hereinafter referred to as slave devices). Only accessories that have passed the authentication can obtain authorization from the terminal device and thus perform its normal functions.
[0003] The master and slave devices mentioned above can be different devices in different application scenarios. For example, in a smart pairing scenario, the master device can be a smartphone, tablet, or other smart terminal, while the slave device can be a wearable device such as a smartwatch, health monitoring bracelet, or smart earphones. In an IoT scenario, the master device can be a gateway or central controller, while the slave device can be various sensors (such as temperature sensors and humidity sensors), smart home appliances (such as smart light bulbs and smart sockets), etc. In an office scenario, the master device can be a printer, and the slave device can be a scanner, ink cartridge, toner cartridge, etc.
[0004] like Figure 1 As shown, in the relevant authentication method, the slave device uses its internally stored and computed key to perform a fixed authentication algorithm on the data sent by the master device, generating a unique calculation result, which is then sent to the master device. The master device then verifies the calculation result; if the verification passes, the execution is successful.
[0005] Research revealed that, given the same data input and the same key, the authentication algorithm consistently produces a fixed result. This makes the authentication process logically simple and lacks variation, allowing attackers to relatively easily simulate the authentication process and subsequently replicate it. Summary of the Invention
[0006] To overcome at least one deficiency in the prior art, this application provides an authentication method, apparatus, storage medium, and electronic device, specifically including:
[0007] In a first aspect, this application provides an authentication method applied to a master device communicating with a slave device, the method comprising:
[0008] Send an authentication request to the slave device, wherein the authentication request is used to instruct the slave device to periodically generate authentication data using a fixed algorithm;
[0009] The slave device obtains the authentication data at a preset time point, wherein the authentication data is the latest authentication data generated by the slave device at the preset time point;
[0010] If the data to be authenticated is different from the expected data at the preset time point, the slave device is determined to have failed authentication.
[0011] Secondly, this application provides an authentication method applied to a slave device communicating with a master device, the method comprising:
[0012] Receive the authentication request sent by the master device;
[0013] In response to the authentication request, authentication data is generated periodically using a fixed algorithm;
[0014] The authentication data to be authenticated at a preset time point is sent to the master device, wherein the authentication data to be authenticated is the latest authentication data generated by the slave device at the preset time point.
[0015] Thirdly, this application provides an authentication device for use with a master device communicating with a slave device, the device comprising:
[0016] An authentication request module is used to send an authentication request to the slave device, wherein the authentication request is used to instruct the slave device to periodically generate authentication data using a fixed algorithm;
[0017] The authentication and discrimination module is used to obtain the authentication data to be authenticated at a preset time point from the slave device, wherein the authentication data to be authenticated is the latest authentication data generated by the slave device at the preset time point;
[0018] The authentication discrimination module is further configured to determine that the slave device has failed authentication if the data to be authenticated is different from the expected data at the preset time point.
[0019] Fourthly, this application provides an authentication device for a slave device communicating with a master device, the device comprising:
[0020] A request receiving module is used to receive authentication requests sent by the master device;
[0021] The request-response module is used to periodically generate authentication data in response to the authentication request using a fixed algorithm.
[0022] The request response module is further configured to send the authentication data to be authenticated at a preset time point to the master device, wherein the authentication data to be authenticated is the latest authentication data generated by the slave device at the preset time point.
[0023] Fifthly, this application provides a storage medium storing a computer program that, when executed by a processor, implements the authentication method.
[0024] Sixthly, this application provides an electronic device, the electronic device including a processor and a memory, the memory storing a computer program, the computer program implementing the authentication method when executed by the processor.
[0025] Compared with the prior art, this application has the following beneficial effects:
[0026] This application provides an authentication method, apparatus, storage medium, and electronic device. The method involves a master device sending an authentication request to a slave device, instructing the slave device to periodically generate authentication data using a fixed algorithm. The master device then obtains authentication data at a preset time point from the slave device. This authentication data is the latest data generated by the slave device at the preset time point. If the authentication data differs from the expected data at the preset time point, the slave device is deemed to have failed authentication. By incorporating a time factor into the device authentication process, the authentication process no longer relies on static data and keys, thereby increasing the difficulty for attackers to crack the authentication. Attached Figure Description
[0027] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0028] Figure 1 A schematic diagram illustrating the principle of an existing authentication method provided in the embodiments of this application;
[0029] Figure 2 One of the flowcharts of the authentication method provided in the embodiments of this application;
[0030] Figure 3 A schematic diagram of a computing node provided in an embodiment of this application;
[0031] Figure 4 A schematic diagram illustrating the time pattern provided in the embodiments of this application;
[0032] Figure 5 A second schematic flowchart illustrating the authentication method provided in this application embodiment;
[0033] Figure 6 One of the structural schematic diagrams of the authentication device provided in the embodiments of this application;
[0034] Figure 7 This is a second schematic diagram of the authentication device provided in the embodiments of this application;
[0035] Figure 8 This is a schematic diagram of the structure of the electronic device provided in the embodiments of this application;
[0036] Figure 9 The circuit structure of the master / slave device provided in the embodiments of this application;
[0037] Figure 10 The current structure of the frequency modification module provided in this application embodiment;
[0038] Figure 11 The circuit structure of the authentication algorithm module provided in the embodiments of this application. Detailed Implementation
[0039] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. The components of the embodiments of this application described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.
[0040] Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of the application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.
[0041] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.
[0042] In the description of this application, it should be noted that the terms "first," "second," "third," etc., are used only for distinguishing descriptions and should not be construed as indicating or implying relative importance. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0043] Based on the above statement, as described in the background section, the authentication algorithm always produces a fixed result for the same data input and the same key. This makes the authentication process logically simple and lacks variation, making it relatively easy for attackers to simulate this authentication process and thus counterfeit it.
[0044] For example, the master device generates a random number and sends it to the slave device. The slave device then receives the random number from the master device, uses the session key and the random number to perform calculations, generates a result, and sends the result back to the master device. Upon receiving the data from the slave device, the master device begins authentication. If authentication succeeds, the master device will execute subsequent functions normally; if authentication fails, the master device will report an error.
[0045] Therefore, for the same data input and the same key, the result of the authentication algorithm is always fixed. This makes the authentication process logically simple and lacks variation, making it relatively easy for attackers to simulate.
[0046] For example, an attacker can collect a sufficient number of data samples, including fixed data sent by the master device and the corresponding encryption results. This data can be obtained from genuine accessories already on the market or extracted from existing products through reverse engineering. The attacker then uses these data samples to reverse engineer and attempt to understand the specific implementation of the authentication algorithm. This may involve a detailed analysis of the hardware and software of the existing accessory to determine the encryption algorithm, key management method, and other relevant parameters used internally. Next, the attacker can write a simulation program that can mimic the behavior of the existing accessory. After debugging, it can be ensured that it can pass the master device's authentication under various conditions, thus completing the counterfeiting.
[0047] Based on the discovery of the aforementioned technical problems, the inventors, through creative labor, proposed the following technical solutions to solve or improve these problems. It should be noted that the deficiencies in the solutions of the prior art are the result of the inventors' practical experience and careful research. Therefore, the discovery process of the aforementioned problems and the solutions proposed in the embodiments of this application below should be considered contributions made by the inventors to this application during the inventive process, and should not be construed as technical content known to those skilled in the art.
[0048] To prevent rapid replication, embodiments of this application (hereinafter referred to as "this embodiment") propose a novel authentication method. This method incorporates a time factor into the authentication process, making it independent of static data and keys, thereby increasing the difficulty for attackers to crack the authentication. For example... Figure 2 As shown, the method includes:
[0049] S1A sends an authentication request to the slave device.
[0050] The authentication request is used to instruct the slave device to periodically generate authentication data using a fixed algorithm.
[0051] S2A obtains the authentication data at a preset time point from the slave device.
[0052] The data to be authenticated is the latest authentication data generated by the device at a preset time point.
[0053] S3A: If the data to be certified is different from the expected data at the preset time point, the device is determined to have failed certification.
[0054] By incorporating a time factor into the device authentication process, the authentication process no longer relies on static data and keys, thus increasing the difficulty for attackers to crack the code.
[0055] To make the solution provided in this embodiment clearer, the printer is used as the master device and the ink cartridge as the slave device, and the following discussion will focus on... Figure 2 Each step in the flowchart is described in detail. However, it should be understood that the operations in the flowchart may not be implemented in sequence, and steps without logical contextual relationships may be reversed in order or performed simultaneously. Furthermore, those skilled in the art, guided by the content of this application, may add one or more other operations to the flowchart, or remove one or more operations from the flowchart. Therefore, please refer to [link to relevant documentation]. Figure 2 The method includes:
[0056] S1A sends an authentication request to the slave device.
[0057] The authentication request is used to instruct the slave device to periodically generate authentication data using a fixed algorithm.
[0058] In this embodiment, the use of a fixed algorithm ensures that the ink cartridge takes the same amount of time to calculate authentication data each time, thereby guaranteeing the predictability of the authentication process. This can be understood as the printer being able to predict the theoretically expected data at each preset time point because the ink cartridge takes the same amount of time to calculate authentication data each time. This allows for a more accurate determination of whether the ink cartridge has completed the authentication calculation on time. If the ink cartridge fails to return the expected authentication data within the predetermined time, the printer can promptly detect the anomaly and take appropriate measures, thereby improving the reliability and security of the entire authentication process.
[0059] In this embodiment, the running cycle of the aforementioned fixed algorithm can be a preset time period for the ink cartridge. Specifically, this time period can be defined as a certain number of clock signals, for example, 1000 clock signals per cycle. Within this cycle, the ink cartridge runs the fixed algorithm to generate one piece of authentication data for that cycle. Then, in the next time cycle, the ink cartridge generates a new piece of authentication data. This ensures the dynamic change of the authentication data. Since the data generated each time is different, it increases the difficulty of counterfeiting.
[0060] Furthermore, since the algorithm is fixed, meaning the algorithm runs for the same amount of time, the cycle can also be the fixed running time of the algorithm. This can be understood as the algorithm completing a full cycle within the same amount of time regardless of when it is started. For example, the algorithm might need 1 second to generate one piece of authentication data. In this case, the cartridge generates one piece of authentication data every 1 second. Therefore, the cartridge generates one piece of authentication data at each fixed time interval. In this embodiment, the end time of each cycle is referred to as an algorithm node, meaning that one piece of authentication data is generated at that algorithm node.
[0061] In this embodiment, the authentication data generated in each cycle is different, thus giving the authentication data a dynamic characteristic. To address this, the ink cartridge can change the input data of the algorithm in each cycle, ensuring that the authentication data generated in each cycle is different. For example, the ink cartridge can use a fixed algorithm with initial data input to generate one authentication data entry; then, this generated authentication data is input into the same algorithm again in the next cycle to obtain new authentication data. This process is repeated continuously. Because the input data changes with each algorithm run, the generated data will be different each time. This mechanism ensures that even if the algorithm itself is fixed, the generated data will continuously change dynamically to facilitate authentication and recognition by the printer.
[0062] For example, an ink cartridge can input initial data into a fixed algorithm to generate authentication data. Then, in the next cycle, the initial data is added to the current cycle number and input into the fixed algorithm again to obtain new authentication data. This process is repeated continuously. Because the input data changes with each algorithm run, the generated data will also be different each time. This mechanism ensures that even if the algorithm itself is fixed, the generated data will continuously and dynamically change to facilitate printer authentication and recognition.
[0063] The initial data mentioned above can be data agreed upon in advance between the ink cartridge and the printer, or it can be generated by the printer and sent to the ink cartridge during each authentication process. Therefore, the authentication request sent by the printer can include the initial data generated by the master device; the initial data is used to instruct the slave device to periodically generate dynamically changing authentication data based on the initial data using a fixed algorithm. This initial data can be a random number generated by the printer using a random algorithm.
[0064] Based on the above description of the authentication request in the embodiments, we will continue with... Figure 2 Step S2A will be explained as follows:
[0065] S2A obtains the authentication data at a preset time point from the slave device.
[0066] The data to be authenticated is the latest authentication data generated by the device at a preset time point.
[0067] In this embodiment, if the ink cartridge cannot actively send data to the printer, the printer can send a data acquisition request to the slave device when a preset time point is reached. The data acquisition request is used to instruct the slave device to send the latest authentication data generated at the preset time point as the data to be authenticated to the master device; thereby receiving the data to be authenticated sent by the slave device.
[0068] Of course, in scenarios where the slave device can actively send data to the master device, the slave device can also send the latest authentication data generated at a preset time point as the data to be authenticated to the master device at each specific time point.
[0069] For example, such as Figure 3 The multiple algorithm nodes shown (node 1 to node N) each generate a piece of authentication data. When the preset time point is between node 1 and node 2, the authentication data generated by node 1 is the most recently generated authentication data from the ink cartridge at that time. Therefore, the authentication data generated by node 1 is sent to the printer as the data to be authenticated. Similarly, when the preset time point is between node 2 and node 3, the authentication data generated by node 2 is the most recently generated authentication data from the ink cartridge at that time. Therefore, the authentication data generated by node 2 is sent to the printer as the data to be authenticated.
[0070] Based on the description of the authentication data in the above embodiments, the following will continue to discuss... Figure 2 Step S3A will be explained as follows:
[0071] S3A: If the data to be certified is different from the expected data at the preset time point, the device is determined to have failed certification.
[0072] This can be understood as follows: during the authentication process, the printer already knows the performance of the original processor used by the ink cartridge and is aware of the algorithm used for the authentication data. In this case, the printer can accurately predict the authentication data that the ink cartridge should calculate at a preset time point based on the algorithm's execution process and the ink cartridge's device performance. For example, the printer can adjust its own device performance to match that of the ink cartridge and run the same algorithm to obtain the expected data at the preset time point. Alternatively, the printer can pre-record the expected data of the ink cartridge at the preset time point.
[0073] Because the authentication data at different nodes is dynamically changing, the printer can compare the received data to be authenticated with the anticipated data. If the received data matches the printer's anticipated data, it indicates that the ink cartridge uses an original processor and the algorithm execution process is as expected, resulting in successful authentication. However, if the received data does not match the anticipated data, meaning the data sent by the ink cartridge does not conform to the printer's prediction, it suggests that the ink cartridge may be using a non-original processor or that there is an anomaly in the algorithm execution process. Therefore, the printer determines that the device has failed authentication.
[0074] In this way, by predicting and comparing the data to be certified, it can be detected whether the ink cartridge uses an original processor, thereby completing the certification of the ink cartridge.
[0075] Furthermore, the number of preset time nodes in this embodiment can be multiple. The printer can verify the ink cartridge multiple times at different time nodes. As long as the data to be certified at any time node is inconsistent with the expected data, the ink cartridge is determined to have failed certification.
[0076] In this embodiment, to further increase the difficulty of cracking the device authentication process, the generation speed of authentication data can be controlled by adjusting the device performance of the ink cartridge. Specifically, the generation speed of the authentication data can be made unpredictable by changing the speed at which the algorithm runs in the ink cartridge, thereby increasing the difficulty of cracking.
[0077] Therefore, in Figure 2 Before step S1A, the printer may also send a speed adjustment request to the ink cartridge, wherein the speed adjustment request includes performance adjustment parameters, which are used to instruct the ink cartridge to adjust the speed at which it generates authentication data.
[0078] In this embodiment, to prevent the performance adjustment parameters from being tampered with during transmission, the verification reference value is used to instruct the slave device to perform verification calculations on the performance adjustment parameters to obtain the verification calculation value; and to determine whether the verification calculation value is consistent with the verification reference value.
[0079] For example, before sending performance tuning parameters, the printer performs some form of verification operation on these parameters (such as hashing, checksum calculation, etc.) to generate a verification reference value. This verification reference value contains a summary of the performance tuning parameters, reflecting their content and structural characteristics. When the ink cartridge receives the performance tuning parameters, it recalculates these parameters using the same verification algorithm to obtain a new verification value; then, the two are compared. If they match, it means the performance tuning parameters have not been tampered with during transmission. At this point, the ink cartridge can send a success flag or an end flag to the printer, or remain silent, and adjust its own device performance according to the performance tuning parameters. Conversely, if they do not match, it means the parameters may have been tampered with during transmission, and the ink cartridge will refuse to accept these parameters and send an error flag or an end flag to the printer.
[0080] This performance adjustment parameter could be the ink cartridge's frequency adjustment information. Since the ink cartridge's frequency adjustment information involves the processor's operating frequency—that is, the number of instruction cycles the processor can complete per second—adjusting the processor's operating frequency can significantly affect the speed at which the algorithm executes within the ink cartridge. For example, if the processor's operating frequency is higher, it can process more instructions per unit time, thus speeding up the generation of authentication data. Conversely, if the operating frequency is lower, the processor processes instructions more slowly, and the generation speed of authentication data will decrease accordingly.
[0081] For example, such as Figure 4 As shown, the ink cartridge can be set to a low-frequency, medium-frequency, or high-frequency clock by adjusting different frequency settings. At different clock frequencies, the ink cartridge generates authentication data at different rates. It is clear that a higher clock frequency results in a smaller time interval between algorithm nodes, meaning faster processing of authentication data.
[0082] Therefore, in this embodiment, by controlling the clock frequency of the ink cartridge, even if an attacker cracks the ink cartridge's performance adjustment process and attempts to imitate it to create a counterfeit product, the original product's clock generator is designed and tested rigorously to ensure stable operation under various environmental conditions. Counterfeit products, due to differences in manufacturing processes, find it difficult to completely replicate the clock generator characteristics of the original product. For example, even minor manufacturing errors can cause deviations in the frequency output of the counterfeit clock generator. This means that even if the counterfeit product is configured with the same frequency adjustment information, it cannot achieve the same frequency adjustment effect as the original product. Therefore, this deviation prevents the counterfeit product from accurately replicating the frequency adjustment effect of the original chip, thus affecting the generation speed of authentication data.
[0083] Thus, by adjusting the performance of the ink cartridge, even if an attacker understands the specific details of the algorithm and the ink cartridge's performance parameters, they cannot accurately predict what authentication data the cartridge should generate at a given time. This also means that adjusting the cartridge's performance leads to changes in the authentication data generation speed, resulting in higher randomness and uncertainty in each generated data. Furthermore, differences in chip manufacturing processes provide additional protection for genuine products, making it impossible for counterfeit products to be functionally equivalent to the originals, further enhancing the overall security of the system.
[0084] In addition to the frequency adjustment information mentioned above, the performance adjustment parameters mentioned above can also be memory access speed or other hardware or software parameters that can affect the speed of algorithm execution.
[0085] In the above embodiments, the authentication method was described from the perspective of the printer. Based on the same inventive concept, the authentication method implemented on an ink cartridge as a slave device will be described below. Figure 5 As shown, the method includes:
[0086] S1B receives authentication requests sent by the master device.
[0087] S2B, in response to authentication requests, periodically generates authentication data using a fixed algorithm.
[0088] S3B sends the authentication data to the master device at a preset time point.
[0089] The data to be authenticated is the latest authentication data generated by the slave device at a preset time point. In this embodiment, if the ink cartridge does not support actively sending data to the printer, the ink cartridge can accept the data acquisition request sent by the printer at the preset time point and then send the data to be authenticated to the master device. If the ink cartridge supports actively sending data to the printer, it can actively send the data to be authenticated to the printer when the preset time point is reached.
[0090] Furthermore, in this embodiment, to ensure that the authentication data is dynamically changing, the cartridge can modify the data input to the algorithm in each cycle. For example, the cartridge can input initial data into a fixed algorithm to generate authentication data. Then, in the next cycle, the cartridge inputs the generated authentication data back into the same fixed algorithm to generate new authentication data. This mechanism ensures continuous dynamic change of the authentication data by constantly using the previously generated data as new input, making each generated data different.
[0091] In addition, the cartridge can employ another method to ensure the authentication data remains consistent. In each cycle, the cartridge inputs initial data into a fixed algorithm to generate a single authentication record. Then, in the next cycle, the cartridge adds the current cycle number to the initial data and inputs it into the fixed algorithm again to generate new authentication data. In this way, the input data changes with each cycle, ensuring that the generated data is different each time.
[0092] The initial data mentioned above can be data agreed upon in advance between the ink cartridge and the printer, or it can be generated by the printer and sent to the ink cartridge via an authentication request during each authentication process. The authentication request sent by the printer includes the printer-generated initial data, which instructs the ink cartridge to periodically generate dynamically changing authentication data based on this initial data using a fixed algorithm. For example, this initial data could be a random number generated by the printer to further increase the unpredictability of data changes.
[0093] Furthermore, to further increase the difficulty of cracking the device authentication process, printers can also control the generation speed of authentication data by adjusting the device performance of the ink cartridges. Therefore, in Figure 5 Before step S1B, the ink cartridge can also receive a speed adjustment request sent by the master device, wherein the speed adjustment request includes performance adjustment parameters; in response to the speed adjustment request, the speed of generating authentication data is adjusted according to the performance adjustment parameters.
[0094] Since the speed at which authentication data is generated is controlled by the slave device's clock, the performance tuning parameter is frequency adjustment information. This can be understood as the frequency adjustment information being used to change the clock frequency, making the processor run faster or slower. If the frequency adjustment information increases the clock frequency, the processor can process more instructions per second, thus speeding up the generation of authentication data. Conversely, if the frequency adjustment information decreases the clock frequency, the processor processes instructions slower, and the generation speed of authentication data will decrease accordingly.
[0095] Thus, by varying the clock frequency, the printer can control the time interval at which the ink cartridge generates authentication data, increasing the difficulty for attackers to predict and mimic the generation process. Even if attackers can grasp the logic of the algorithm itself, differences in manufacturing processes make it difficult for counterfeiters to quickly design a clock generator that is exactly the same as the original product, making it difficult for counterfeiters to complete authentication.
[0096] Based on the same inventive concept as the authentication method provided in this embodiment, this embodiment also provides an authentication device for a master device communicating with a slave device. This device includes at least one software functional module that can be stored in a memory in software form. A processor in the master device executes the executable module stored in the memory. For example, the software functional module and computer program included in this device. Please refer to... Figure 6 Functionally, the device may include:
[0097] The authentication request module 11A is used to send an authentication request to the slave device, wherein the authentication request is used to instruct the slave device to periodically generate authentication data through a fixed algorithm.
[0098] The authentication discrimination module 12A is used to obtain the authentication data to be authenticated at a preset time point from the slave device, wherein the authentication data to be authenticated is the latest authentication data generated by the slave device at the preset time point.
[0099] The authentication discrimination module 12A is also used to determine that the slave device has failed authentication if the data to be authenticated is different from the expected data at a preset time point.
[0100] In this embodiment, the authentication request module 11A is used to implement Figure 2 In step S1A, the authentication discrimination module 12A is used to implement... Figure 2 Therefore, for detailed descriptions of each of the above modules, please refer to the specific implementation methods of the corresponding steps.
[0101] Furthermore, since it shares the same inventive concept as the authentication method applied to a master device communicating with a slave device, the authentication device can also implement other steps or sub-steps of the method through the aforementioned modules.
[0102] Optionally, before sending the authentication request to the slave device, the authentication request module 11A is further configured to:
[0103] A speed adjustment request is sent to the slave device, wherein the speed adjustment request includes performance adjustment parameters, which are used to instruct the slave device to adjust the speed at which authentication data is generated.
[0104] Optionally, the authentication and discrimination module 12A is also specifically used for:
[0105] When the preset time point is reached, a data acquisition request is sent to the slave device. The data acquisition request is used to instruct the slave device to send the latest authentication data generated at the preset time point as the data to be authenticated to the master device.
[0106] Receive authentication data sent from the device.
[0107] Based on the same inventive concept as the authentication method provided in this embodiment, this embodiment also provides an authentication device for a slave device communicating with a master device. This device includes at least one software functional module that can be stored in a memory in software form. A processor in the slave device executes the executable module stored in the memory. For example, the software functional module and computer program included in the device. Please refer to... Figure 7 Functionally, the device may include:
[0108] The request receiving module 11B is used to receive authentication requests sent by the master device;
[0109] The request response module 12B is used to respond to authentication requests by periodically generating authentication data using a fixed algorithm.
[0110] The request response module 12B is also used to send the authentication data to be authenticated at a preset time point to the master device, wherein the authentication data to be authenticated is the latest authentication data generated by the slave device at the preset time point.
[0111] In this embodiment, the request receiving module 11B is used to implement Figure 5 In S1B, the request and response module 12B is used to implement... Figure 5 S2B and S3B in the above. Therefore, for a detailed description of each of the above modules, please refer to the specific implementation method of the corresponding step.
[0112] Furthermore, since it shares the same inventive concept as the authentication method applied to a slave device communicating with a master device, the authentication device can also implement other steps or sub-steps of the method through the aforementioned modules.
[0113] Optionally, the request receiving module 11B is also used for:
[0114] Receive a speed adjustment request sent by the master device, wherein the speed adjustment request includes performance adjustment parameters.
[0115] Request / response module 12B is also used for:
[0116] In response to a speed adjustment request, the speed at which authentication data is generated is adjusted according to performance adjustment parameters.
[0117] Optionally, the speed at which authentication data is generated is controlled by the slave device's clock, with the performance tuning parameter being frequency adjustment information. The request-response module 12B is also specifically used for:
[0118] The clock frequency is adjusted based on the frequency adjustment information.
[0119] In addition, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.
[0120] It should also be understood that if the above embodiments are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application.
[0121] Therefore, this embodiment also provides a storage medium, which is a computer-readable storage medium. The storage medium stores a computer program, which, when executed by a processor, implements the authentication method provided in this embodiment. This method can be applied to a master device communicating with a slave device or to a slave device communicating with a master device. The storage medium can be any medium capable of storing program code, such as a USB flash drive, portable hard drive, read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.
[0122] This embodiment provides an electronic device that implements the above-described authentication method. For example... Figure 8 As shown, the electronic device may include a processor 22 and a memory 21. The memory 21 stores a computer program, and the processor implements the authentication method provided in this embodiment by reading and executing the computer program corresponding to the above-described embodiments. This method can be applied to a master device communicating with a slave device or to a slave device communicating with a master device.
[0123] See also Figure 8 The electronic device also includes a communication unit 23. The memory 21, processor 22 and communication unit 23 are electrically connected to each other directly or indirectly through system bus 24 to realize data transmission or interaction.
[0124] The memory 21 can be an information recording device based on any electronic, magnetic, optical, or other physical principles, used to record execution instructions, data, etc. In some embodiments, the memory 21 can be, but is not limited to, volatile memory, non-volatile memory, memory drive, etc.
[0125] In some embodiments, the volatile memory may be random access memory (RAM); in some embodiments, the non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash memory, etc.; in some embodiments, the storage drive may be a disk drive, solid-state drive, any type of storage disk (such as optical disc, DVD, etc.), or similar storage media, or a combination thereof.
[0126] The communication unit 23 is used to send and receive data over a network. In some embodiments, the network may include a wired network, a wireless network, a fiber optic network, a telecommunications network, an intranet, the Internet, a local area network (LAN), a wide area network (WAN), a wireless local area network (WLAN), a metropolitan area network (MAN), a public switched telephone network (PSTN), a Bluetooth network, a ZigBee network, or a near field communication (NFC) network, or any combination thereof. In some embodiments, the network may include one or more network access points. For example, the network may include wired or wireless network access points, such as base stations and / or network switching nodes, through which one or more components of the service request processing system can connect to the network to exchange data and / or information.
[0127] The processor 22 may be an integrated circuit chip with signal processing capabilities, and may include one or more processing cores (e.g., a single-core processor or a multi-core processor). By way of example only, the processor described above may include a Central Processing Unit (CPU), an Application Specific Integrated Circuit (ASIC), an Application Specific Instruction-set Processor (ASIP), a Graphics Processing Unit (GPU), a Physics Processing Unit (PPU), a Digital Signal Processor (DSP), a Field Programmable Gate Array (FPGA), a Programmable Logic Device (PLD), a controller, a microcontroller unit, a Reduced Instruction Set Computing (RISC) computer, or a microprocessor, or any combination thereof.
[0128] Understandable. Figure 8 The structure shown is for illustrative purposes only. Electronic devices may also have more advanced features. Figure 8 Showing more or fewer components, or having with Figure 8 The different configurations shown are worth noting. Figure 8 The components shown can be implemented in hardware, software, or a combination thereof. That is to say, the implementation of the processing flow in the above embodiments is not limited to the processor reading and running purely computer-readable program code from memory, but can also be implemented through hardware or logic devices.
[0129] It should also be understood that improvements to a technology can be divided into hardware improvements (e.g., improvements to the circuit structure of diodes, transistors, switches, etc.) and software improvements (improvements to the methodology). However, with technological advancements, many improvements to the methodology can now be considered direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved methodology into the hardware circuit. Therefore, it cannot be said that an improvement to the methodology cannot be implemented using a hardware physical module. For example, a Programmable Logic Device (PLD) (e.g., a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logic function is determined by the user programming the device. Designers can program a digital system themselves to "integrate" it onto a PLD, without needing chip manufacturers to design and manufacture dedicated integrated circuit chips. Furthermore, nowadays, instead of manually manufacturing integrated circuit chips, this programming is mostly implemented using "logic compiler" software. Similar to the software compiler used in program development, the original code before compilation must be written in a specific programming language, called a Hardware Description Language (HDL). There are many HDLs, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, and RHDL (Ruby Hardware Description Language). Currently, VHDL (Very High Speed Integrated Circuit Hardware Description Language) and Verilog are the most commonly used.
[0130] Therefore, those skilled in the art should also understand that by simply performing some logic programming on the method flow using the aforementioned hardware description languages and programming it into an integrated circuit, the hardware circuit that implements the logic method flow can be easily obtained.
[0131] like Figure 9As shown, from a circuit implementation perspective, the master or slave device in this embodiment may include a communication module 31, an authentication algorithm module 33, and a frequency modification module 32. The communication module 31 can be configured as a common Inter-Integrated Circuit (IIC) transceiver, Serial Peripheral Interface (SPI) transceiver, etc., and its communication command format can be defined as:
[0132] The first instruction is: The master device sends performance tuning parameters and verification reference values based on these parameters. Upon receiving this information, the slave device will send a response including a success or failure flag.
[0133] The second instruction is: the master device sends authentication data and requests data from the slave device at a specific time. Upon receiving the request, the slave device will provide the data to be authenticated.
[0134] The following explanation uses a device as an example to further illustrate the frequency modification module 32. Figure 10 As shown, Figure 9 The frequency modification module 32 includes a verification algorithm circuit 321, a comparator 323, a clock generator 322, and a clock selector 324. The frequency modification module 32 operates as follows:
[0135] (1) The clock generator 322 contains multiple clock signals of different frequencies. These clock signals can be selected and switched by the clock generator 322 according to the frequency adjustment information.
[0136] (2) The verification algorithm circuit 321 is used to receive frequency adjustment information, calculate the algorithm result and send it to the comparator 323;
[0137] (3) Comparator 323 is responsible for comparing the result calculated by the verification algorithm circuit 321 with the preset verification reference value. If the calculation result is consistent with the verification reference value, comparator 323 outputs a success flag; if they are inconsistent, it outputs a failure flag.
[0138] (4) Clock selector 324 selects an output clock signal from multiple clock signals based on the output (i.e., the valid flag) of comparator 323 and the frequency adjustment information. If the frequency adjustment information is valid, clock selector 324 will select a suitable clock frequency for output; otherwise, it will output the default clock signal.
[0139] The verification algorithm can be defined as a standard security algorithm or a custom algorithm. Its key can be set to a fixed value / stored in memory or additional instructions can be added before the first instruction to interact with / generate the key. The clock generator 322 can be designed as a single clock with frequency adjustment functionality. The frequency adjustment information serves as the input to the clock generator 322, and the valid flag output by the comparator 323 directly serves as the valid flag for the frequency adjustment information.
[0140] like Figure 11 As shown, Figure 9 The authentication algorithm module 33 includes a node controller 331, an authentication algorithm circuit 332, and an algorithm result register 333. The authentication algorithm module 33 operates as follows:
[0141] (1) Before the algorithm starts, the node controller 331 will send a reset signal to reset the algorithm result register 333 to the initial value or a fixed value. This is to ensure that the algorithm is in a known initial state at the beginning and to avoid the uncertainty caused by the previous state from affecting the authentication process.
[0142] (2) The node controller 331 generates an algorithm start flag and sends it to the authentication algorithm circuit 332. This marks the official start of the algorithm execution. At this time, the authentication algorithm circuit 332 is ready to accept input data and begin processing.
[0143] (3) The authentication algorithm circuit 332 starts working. The input data can be the initial data sent by the master device or the result calculated by the previous node. When the algorithm reaches a certain node, the authentication algorithm circuit 332 will send a node completion flag to the node controller 331. The node controller 331 will receive this flag and prepare to process the next operation.
[0144] (4) The node controller 331 generates an enable signal and a clock signal. The enable signal is used to activate the algorithm circuit to perform the next calculation, while the clock signal is used to synchronize the execution of the algorithm to ensure that each step is performed at a predetermined time interval.
[0145] (5) The algorithm result register 333 reads data from the authentication algorithm circuit 332 and stores this data as the authentication data for the current time node. In this way, each time the algorithm executes to a node, the latest authentication data will be saved for subsequent comparison and verification.
[0146] (6) Repeat steps (3) to (5) above at other time points. This ensures that the authentication algorithm can continuously generate and store the latest authentication data throughout the authentication process until the algorithm is completed.
[0147] (7) When the authentication algorithm reaches the endpoint, the authentication algorithm circuit 332 sends a completion flag to the node controller 331. Upon receiving this completion flag, the node controller 331 generates a new enable signal and a clock signal, updating the value of the algorithm result register 333. Simultaneously, the node controller 331 enters the time overflow point, generates a reset signal again, and resets the algorithm result register 333 to its initial or fixed value, preparing for the next round of algorithm execution.
[0148] After receiving the completion flag for a period of time, the node controller 331 enters the time overflow point and generates a reset signal to reset the algorithm result register 333 to the initial value / fixed value.
[0149] Additionally, when node controller 331 receives feedback flag information, its generated control signal causes the authentication algorithm to stop working. Simultaneously, the enable signal and clock signal generated by node controller 331 update the value of algorithm result register 333. This updated data is transmitted to the communication module for further reading and output. In this way, the authentication algorithm module ensures that the latest authentication data generated during algorithm execution is accurately stored and transmitted for subsequent verification.
[0150] It should be understood that the selection of authentication algorithms and their nodes is flexible. It can be a split or repetition of a standard algorithm, or a split of a single, custom-defined algorithm, or a combination of multiple algorithms. This flexibility allows the system to be customized according to specific application scenarios and requirements, thereby improving the accuracy and security of authentication.
[0151] Thus, by introducing a time factor into the authentication process, the output of the authentication algorithm is no longer fixed, but depends on a specific point in time and the length of time the algorithm takes to execute. Even with the same input data and key, the result of each authentication will differ. This variability greatly increases the difficulty of counterfeiting, because attackers cannot replicate the authentication process through simple data collection and reverse engineering.
[0152] Secondly, the collaborative operation of the frequency modification module 32 and the authentication algorithm module 33 further enhances the security of authentication. The frequency modification module 32 can select an appropriate clock signal based on the received frequency adjustment information, ensuring that the algorithm can run at different frequencies. The frequency variation increases the difficulty for counterfeiters to replicate the algorithm, because even if attackers master the specific details of the algorithm, they will find it difficult to accurately simulate the algorithm execution process at different frequencies.
[0153] The authentication algorithm module 33 manages and controls the execution process of the algorithm through the node controller 331. The node controller 331 ensures that the calculation results of each node are accurately recorded and verified. Furthermore, the node controller 331 can generate corresponding flag information according to different stages of the algorithm to ensure that the algorithm provides feedback and resets at the correct time. For example, when the algorithm reaches a critical node, the node controller 331 generates a node completion flag, notifying the algorithm module to proceed to the next step. This fine-grained control and management mechanism ensures the reliability and consistency of the entire authentication process.
[0154] It should be understood that the apparatus and methods disclosed in the above embodiments can also be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the architecture, functionality, and operation of possible implementations of apparatus, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.
[0155] The above descriptions are merely various embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. An authentication method, characterized in that, The method, applied to a master device communicating with slave devices, includes: An authentication request is sent to the slave device, wherein the authentication request is used to instruct the slave device to periodically generate authentication data using a fixed algorithm, and the device performance of the slave device controls the generation speed of the authentication data; The slave device obtains the authentication data at a preset time point, wherein the authentication data is the latest authentication data generated by the slave device at the preset time point; If the data to be authenticated is different from the expected data at the preset time point, the slave device is determined to have failed authentication.
2. The authentication method according to claim 1, characterized in that, Before sending the authentication request to the slave device, the method further includes: A speed adjustment request is sent to the slave device, wherein the speed adjustment request includes performance adjustment parameters, which are used to instruct the slave device to adjust the speed at which the authentication data is generated.
3. The authentication method according to claim 2, characterized in that, The speed adjustment request also includes a verification reference value; The verification reference value is used to instruct the slave device to perform verification calculations on the performance adjustment parameters to obtain a verification calculation value; and to determine whether the verification calculation value is consistent with the verification reference value.
4. The authentication method according to claim 1, characterized in that, The authentication request includes the initial data generated by the master device; The initial data is used to instruct the slave device to periodically generate authentication data based on the initial data using a fixed algorithm.
5. The authentication method according to claim 1 or 4, characterized in that, The authentication data generated in each cycle is different.
6. The authentication method according to claim 1, characterized in that, Obtaining the authentication data at a preset time point from the slave device includes: When the preset time point is reached, a data acquisition request is sent to the slave device, wherein the data acquisition request is used to instruct the slave device to send the latest authentication data generated at the preset time point as the data to be authenticated to the master device; Receive the authentication data sent by the slave device.
7. An authentication method, characterized in that, The method, applied to a slave device communicating with a master device, includes: Receive the authentication request sent by the master device; In response to the authentication request, authentication data is periodically generated using a fixed algorithm, wherein the device performance of the slave device controls the generation speed of the authentication data; The authentication data to be authenticated at a preset time point is sent to the master device, wherein the authentication data to be authenticated is the latest authentication data generated by the slave device at the preset time point.
8. The authentication method according to claim 7, characterized in that, The authentication request includes initial data generated by the master device, and authentication data is periodically generated using a fixed algorithm, including: Based on the initial data, authentication data is periodically generated using a fixed algorithm.
9. The authentication method according to claim 7 or 8, characterized in that, The authentication data generated in each cycle is different.
10. The authentication method according to claim 7, characterized in that, Before receiving the authentication request sent by the master device, the method further includes: Receive a speed adjustment request sent by the master device, wherein the speed adjustment request includes performance adjustment parameters; In response to the speed adjustment request, the speed at which the authentication data is generated is adjusted according to the performance adjustment parameters.
11. The authentication method according to claim 10, characterized in that, The speed at which the authentication data is generated is controlled by the clock of the slave device. The performance adjustment parameter is frequency adjustment information. Adjusting the speed at which the authentication data is generated according to the performance adjustment parameter includes: The clock frequency of the clock is adjusted according to the frequency adjustment information.
12. An authentication device, characterized in that, The device is used as a master device for communicating with slave devices, and the device includes: An authentication request module is used to send an authentication request to the slave device, wherein the authentication request is used to instruct the slave device to periodically generate authentication data through a fixed algorithm, and the device performance of the slave device controls the generation speed of the authentication data; The authentication and discrimination module is used to obtain the authentication data to be authenticated at a preset time point from the slave device, wherein the authentication data to be authenticated is the latest authentication data generated by the slave device at the preset time point; The authentication discrimination module is further configured to determine that the slave device has failed authentication if the data to be authenticated is different from the expected data at the preset time point.
13. An authentication device, characterized in that, A slave device used for communicating with a master device, the apparatus comprising: A request receiving module is used to receive authentication requests sent by the master device; A request-response module is used to respond to the authentication request by periodically generating authentication data using a fixed algorithm, wherein the device performance of the slave device controls the generation speed of the authentication data. The request response module is further configured to send the authentication data to be authenticated at a preset time point to the master device, wherein the authentication data to be authenticated is the latest authentication data generated by the slave device at the preset time point.
14. A storage medium, characterized in that, The storage medium stores a computer program that, when executed by a processor, implements the authentication method according to any one of claims 1-6 or 7-11.
15. An electronic device, characterized in that, The electronic device includes a processor and a memory, the memory storing a computer program that, when executed by the processor, implements the authentication method according to any one of claims 1-6 or 7-11.